FORSMILE
JA
セキュリティ2026/06/29

[URGENT] Linux Kernel CVE-2026-46331: Update Stable Kernels — Local tc pedit Privilege Escalation

Partial copy-on-write handling in tc pedit can corrupt page-cache data. This is a local CAP_NET_ADMIN attack, not remote RCE. Install a fixed distribution kernel.

← Back to Blog

CVE-2026-46331 is a Linux kernel flaw in tc pedit where an incorrect writable-range calculation can leave part of a shared skb or page-cache-backed region outside copy-on-write protection. This is not unauthenticated remote RCE. Exploitation requires local ability to configure tc/rtnetlink with CAP_NET_ADMIN. The Linux CNA rates it CVSS v3.1 7.8 HIGH.

Vulnerability Overview and Scope of Impact

Fixed stable-version floors are 5.10.260, 5.15.211, 6.1.177, 6.6.144, 6.12.94, 6.18.36, 7.0.13, and 7.1. Linux distributions may backport the fix without adopting the upstream version number, so administrators must also consult the advisory and package status from their distribution.

A wide range of OS distributions are affected by this vulnerability, with root privilege escalation verified on RHEL 10.0, Debian 13 Trixie, and Ubuntu 24.04.4. Red Hat published an official advisory (RHSB-2026-008) on June 19, 2026, confirming the impact on RHEL 8, 9, 10, and related products including OpenShift and OpenStack.

⚠ CVE Score — 高危険度 / HIGH
7.8HIGHCVSS v3.1CVE-2026-46331

Specific Impact and Attack Scenarios

Attackers could exploit this vulnerability to execute arbitrary code on a vulnerable Linux system, ultimately gaining root privileges. This could lead to severe damage, such as tampering with system configurations, stealing confidential information, installing backdoors, or even using the system as a stepping stone for attacks on other systems. Since PoC code has already been released, the risk of exploitation is extremely high, posing a serious threat to organizational security postures.

Immediate Countermeasures for Engineers

Install the fixed kernel package from the distribution and, after reboot, verify that the running kernel matches the corrected package. Review unnecessary user namespaces and grants of CAP_NET_ADMIN. Dirty Pipe (CVE-2022-0847) has a different cause and affected range and must not be presented as this CVE's equivalent or fix.

📦
Search Amazon US for related books and tools
cybersecurity server security tools
Search Amazon US → (affiliate link). As an Amazon Associate, we earn from qualifying purchases.

Reference Sources and Official Patch Information

Related articles