CVE Tools

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

The Hacker NewsBy The Hacker News

PoC publiclinux kernelandroid

Our summary

A newly disclosed Linux kernel issue called “Bad Epoll” (CVE-2026-46242) enables unprivileged local users to gain root access. It impacts Linux systems and Android devices that run affected kernel builds, because an epoll use-after-free race can corrupt kernel memory and turn a normal account into full control. Fixes are available via upstream (commit a6dc643c69311677c574a0f17a3f4d66a5f3744b) and distribution backports, and timing makes the bug hard but the published proof of concept reliably achieves escalation on tested setups.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store