CVE Tools

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

The Hacker NewsBy The Hacker News

PoC publicLinux Kernel

Our summary

A Linux kernel vulnerability in the traffic-control packet-editing action (act_pedit), tracked as CVE-2026-46331 (“pedit COW”), can allow an unprivileged local user to gain root. The issue is an out-of-bounds write that corrupts shared page-cache content, enabling an attacker to poison the in-memory copy of /bin/su without touching the disk, bypassing file integrity checks after exploitation. Public working exploits appeared shortly after the CVE was assigned, and Red Hat, Debian, and Ubuntu kernels are affected (per their advisories), making timely patching and mitigation important for multi-tenant and containerized environments.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store