Linux Kernel Releases Security Updates for Information Disclosure Vulnerability
Successful exploitation of CVE‑2026‑46333 could allow local attackers to disclose sensitive system files on affected Linux systems
Summary
Successful exploitation of CVE‑2026‑46333 could allow local attackers to disclose sensitive system files on affected Linux systems
Affected platforms
The following platforms are known to be affected:
Threat details
Proof-of-Concept Exploit
Public proof‑of‑concept exploit code for CVE‑2026‑46333 (also referred to as ssh‑keysign‑pwn) is available. Exploitation is local‑only but may result in disclosure of sensitive files, including SSH host keys and password hashes.
The NHS England National CSOC assesses exploitation as highly likely.
Introduction
The Linux kernel project has released a security advisory to address a medium severity vulnerability in the Linux kernel. Successful exploitation could allow a local attacker to read sensitive files opened by privileged processes.
- CVE‑2026‑46333 – "Improper access control / race condition in ptrace dumpability logic" vulnerability – CVSS v3.1 score: 5.5
Remediation advice
Affected organisations are encouraged to review the CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic advisory and to apply the relevant kernel updates as soon as possible.
Definitive source of threat updates
Last edited: 20 May 2026 3:29 pm