PT-2026-49625 · Linux+1 · Linux Kernel+1

·

CVE-2026-46331

·

Published

2026-05-18

·

Updated

2026-07-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds write flaw exists in the traffic control packet editing (pedit) subsystem of the Linux kernel. In the tcf pedit act() function, the copy-on-write (COW) range for skb ensure writable() is computed once before iterating over edit keys using tcfp off max hint. However, this calculation fails to account for runtime header offsets added by typed keys, leaving part of the target write region without a proper copy-on-write. This allows a local unprivileged attacker to corrupt shared page-cache memory, potentially poisoning cached privileged binaries in memory (such as /bin/su) without altering the files on disk. This can be exploited to escalate privileges to root or cause a system crash. The issue is particularly exploitable in environments where unprivileged user namespaces are enabled.
Recommendations Apply vendor kernel updates immediately and reboot the system. Restrict the use of unprivileged user namespaces where operationally feasible. Monitor for unusual usage of the tc and unshare commands.

Exploit

Fix

LPE

DoS

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:27288
ALSA-2026:27353
ALSA-2026:27354
ALSA-2026:27789
BDU:2026-08426
CVE-2026-46331
ECHO-170F-91A6-557D
OESA-2026-2870
RHSA-2026:27288
RHSA-2026:27353
RHSA-2026:27354
RHSA-2026:27355
RHSA-2026:27704
RHSA-2026:27705
RHSA-2026:27706
RHSA-2026:27707
RHSA-2026:27708
RHSA-2026:27709
RHSA-2026:27713
RHSA-2026:27731
RHSA-2026:27789
RHSA-2026:33666
SUSE-SU-2026:2195-1
SUSE-SU-2026:2238-1
SUSE-SU-2026:22521-1
SUSE-SU-2026:22522-1
SUSE-SU-2026:22665-1
SUSE-SU-2026:22666-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1
SUSE-SU-2026:2839-1
SUSE-SU-2026:2840-1
SUSE-SU-2026:2841-1
SUSE-SU-2026:2914-1
SUSE-SU-2026:3044-1
SUSE-SU-2026:3089-1
SUSE-SU-2026:3156-1

Affected Products

Linux Kernel
Rocky Linux