Skip to main content

Linux Kernel Releases Security Updates for Information Disclosure Vulnerability

Successful exploitation of CVE‑2026‑46333 could allow local attackers to disclose sensitive system files on affected Linux systems

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE‑2026‑46333 could allow local attackers to disclose sensitive system files on affected Linux systems


Threat details

Proof-of-Concept Exploit

Public proof‑of‑concept exploit code for CVE‑2026‑46333 (also referred to as ssh‑keysign‑pwn) is available. Exploitation is local‑only but may result in disclosure of sensitive files, including SSH host keys and password hashes.

The NHS England National CSOC assesses exploitation as highly likely. 


Introduction

The Linux kernel project has released a security advisory to address a medium severity vulnerability in the Linux kernel. Successful exploitation could allow a local attacker to read sensitive files opened by privileged processes.

  • CVE‑2026‑46333 – "Improper access control / race condition in ptrace dumpability logic" vulnerability – CVSS v3.1 score: 5.5

Remediation advice

Affected organisations are encouraged to review the CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic advisory and to apply the relevant kernel updates as soon as possible.



Last edited: 20 May 2026 3:29 pm