In the Linux kernel, the following vulnerability has been resolved:
ptrace: slightly saner 'get_dumpable()' logic
The 'dumpability' of a task is fundamentally about the memory image of
the task - the concept comes from whether it can core dump or not - and
makes no sense when you don't have an associated mm.
And almost all users do in fact use it only for the case where the task
has a mm pointer.
But we have one odd special case: ptrace_may_access() uses 'dumpable' to
check various other things entirely independently of the MM (typically
explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for
threads that no longer have a VM (and maybe never did, like most kernel
threads).
It's not what this flag was designed for, but it is what it is.
The ptrace code does check that the uid/gid matches, so you do have to
be uid-0 to see kernel thread details, but this means that the
traditional "drop capabilities" model doesn't make any difference for
this all.
Make it all make a *bit* more sense by saying that if you don't have a
MM pointer, we'll use a cached "last dumpability" flag if the thread
ever had a MM (it will be zero for kernel threads since it is never
set), and require a proper CAP_SYS_PTRACE capability to override.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
14 Jul 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Jul 2026, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46333.json - Product, Third Party Advisory |
30 Jun 2026, 14:04
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Debian
Debian debian Linux Linux linux Kernel Linux |
|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* |
|
| References | () https://git.kernel.org/stable/c/01363cb3fbd0238ffdeb09f53e9039c9edf8a730 - Patch | |
| References | () https://git.kernel.org/stable/c/15b828a46f305ae9f05a7c16914b3ce273474205 - Patch | |
| References | () https://git.kernel.org/stable/c/2a93a4fac7b6051d3be7cd1b015fe7320cd0404d - Patch | |
| References | () https://git.kernel.org/stable/c/31e62c2ebbfdc3fe3dbdf5e02c92a9dc67087a3a - Patch | |
| References | () https://git.kernel.org/stable/c/4709234fd1b95136ceb789f639b1e7ea5de1b181 - Patch | |
| References | () https://git.kernel.org/stable/c/6e5b51e74a40d377bcd3081dd33fbaa0e1aa7e3d - Patch | |
| References | () https://git.kernel.org/stable/c/8f907d345bae8f4b3f004c5abc56bf2dfb851ea7 - Patch | |
| References | () https://git.kernel.org/stable/c/93d4ba49d18e3d7fb41a9927c2d0cca5e9dfefd6 - Patch | |
| References | () http://www.openwall.com/lists/oss-security/2026/05/15/9 - Mailing List | |
| References | () http://www.openwall.com/lists/oss-security/2026/05/20/14 - Mailing List | |
| References | () http://www.openwall.com/lists/oss-security/2026/05/20/16 - Mailing List | |
| References | () https://lists.debian.org/debian-lts-announce/2026/05/msg00032.html - Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2026/05/msg00035.html - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19521 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19540 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19568 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19569 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19664 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19666 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19705 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19711 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:19875 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:20051 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:20054 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:20129 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:20130 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:20299 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:20593 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:21701 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:21702 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:23468 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:23469 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:23470 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:23471 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:24814 - Third Party Advisory | |
| References | () https://access.redhat.com/security/cve/CVE-2026-46333 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2477802 - Third Party Advisory | |
| References | () https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn/ - Exploit, Third Party Advisory | |
| References | () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46333.json - Third Party Advisory, Product |
30 Jun 2026, 03:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
19 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CWE | CWE-269 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
18 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
15 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
15 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-15 14:16
Updated : 2026-07-15 02:22
NVD link : CVE-2026-46333
Mitre link : CVE-2026-46333
CVE.ORG link : CVE-2026-46333
JSON object : View
Products Affected
debian
- debian_linux
linux
- linux_kernel
CWE
CWE-269
Improper Privilege Management
