CVE detail
CVE-2026-46333
In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don't have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses 'dumpable' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for threads that no longer have a VM (and maybe never did, like most kernel threads). It's not what this flag was designed for, but it is what it is. The ptrace code does check that the uid/gid matches, so you do have to be uid-0 to see kernel thread details, but this means that the traditional "drop capabilities" model doesn't make any difference for this all. Make it all make a *bit* more sense by saying that if you don't have a MM pointer, we'll use a cached "last dumpability" flag if the thread ever had a MM (it will be zero for kernel threads since it is never set), and require a proper CAP_SYS_PTRACE capability to override.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
49 source links · newest first
00 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-4
governmentwww.cisa.govJul 28, 2026, 12:00 PMCVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C CVE-2026-43284 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_
governmentwww.cisa.govJun 23, 2026, 12:00 PMcheck codes now return richer detail for users. New module content (5) Paperclip AI RCE using a chain of six API calls (CVE-2026-41679) Authors: Sagilayani https://github.com/sagilayani and h00die-gr3y [email protected] Type: Exploit Pull request: #21547 contributed by h00die-gr3y Path: linux/http/paperclipai_unauth_rce_cve_2026_41679 AttackerKB re
vendorwww.rapid7.comJun 19, 2026, 5:08 PMA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. CVE-2026-9082: Drupal’s Highly Critical SQL Injection Flaw Is Already Under Active Attack Why pure extortion is […]
newssecurityaffairs.comMay 24, 2026, 11:51 AMLinked URL: https://blog.qualys.com/vulnerabilities-threat-research/2026/05/20/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path | Posted by signa11 | 1 points | 0 comments
communitynews.ycombinator.comMay 24, 2026, 7:39 AM- DirtyDecrypt: PoC Released for yet another Linux flawSecurity Affairs
DirtyDecrypt (CVE-2026-31635): working PoC out for a Linux kernel LPE flaw. Missing COW guard in rxgk_decrypt_skb lets local attackers reach root. After Copy Fail, Dirty Frag, and Fragnesia, here comes DirtyDecrypt, another local privilege escalation vulnerability in the kernel, this time with a working proof-of-concept already out in the open. The flaw was discovered and […]
newssecurityaffairs.comMay 20, 2026, 7:36 AM Information published.
vendormsrc.microsoft.comMay 16, 2026, 8:05 AM- CVE-2026-46333 (SSH-keysign-pwn)Hacker News
Linked URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46333 | Posted by ethanplant | 3 points | 0 comments
communitynews.ycombinator.comMay 15, 2026, 10:11 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46333.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 15, 2026, 2:16 PM No excerpt available.
Exploitgithub.comMay 15, 2026, 2:16 PM- https://cert-portal.siemens.com/productcert/html/ssa-019113.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMay 15, 2026, 2:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2477802bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/security/cve/CVE-2026-46333access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:33486access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:24814access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:23471access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:23470access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:23469access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:23468access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:21702access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:21701access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:20593access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:20299access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:20130access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:20129access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:20054access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:20051access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:19875access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:19711access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:19705access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:19666access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:19664access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:19569access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:19568access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:19540access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:19521access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 2:16 PM No excerpt available.
Vendor Advisorylists.debian.orgMay 15, 2026, 2:16 PMNo excerpt available.
Vendor Advisorylists.debian.orgMay 15, 2026, 2:16 PM- http://www.openwall.com/lists/oss-security/2026/05/20/16www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 15, 2026, 2:16 PM - http://www.openwall.com/lists/oss-security/2026/05/20/14www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 15, 2026, 2:16 PM - http://www.openwall.com/lists/oss-security/2026/05/15/9www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 15, 2026, 2:16 PM No excerpt available.
Vendor Advisorygit.kernel.orgMay 15, 2026, 2:16 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 15, 2026, 2:16 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 15, 2026, 2:16 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 15, 2026, 2:16 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 15, 2026, 2:16 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 15, 2026, 2:16 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 15, 2026, 2:16 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 15, 2026, 2:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- 0xdeadbeefnetwork/ssh-keysign-pwnHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 14, 2026, 3:11 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-31676CVSS 7.8 · High
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate p…
- CVE-2022-25636CVSS 7.8 · High
net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offl…
- CVE-2012-1104CVSS 5.3 · Medium
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
- CVE-2018-10853CVSS 7.0 · High
A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emu…
- CVE-2018-13405CVSS 7.8 · High
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory…
- CVE-2015-0239CVSS 4.4 · Medium
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS p…