CVE-2026-46331Disclosure(linux / linux_kernel)

CRITICALCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 22 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 111 mentions across 30 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 20 signals
  • PoC mentioned or linked in 44 signals
  • Patch or workaround mentioned in 28 signals
  • Technical details provided in 87 signals
  • Disclosure: 29 classified signals
  • Peaked 26d ago at 22 mentions (2026-06-26); latest day: 1
  • 111 total mentions across 30 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline111 mentions / 30d
06111722Mentions · 2026-06-16: 2Mentions · 2026-06-17: 1Mentions · 2026-06-25: 1Mentions · 2026-06-26: 22Mentions · 2026-06-27: 14Mentions · 2026-06-28: 12Mentions · 2026-06-29: 13Mentions · 2026-06-30: 2Mentions · 2026-07-01: 3Mentions · 2026-07-02: 2Mentions · 2026-07-03: 2Mentions · 2026-07-04: 2Mentions · 2026-07-05: 1Mentions · 2026-07-06: 1Mentions · 2026-07-09: 1Mentions · 2026-07-12: 2Mentions · 2026-07-18: 3Mentions · 2026-07-22: 1Mentions · 2026-07-23: 3Mentions · 2026-07-24: 5Mentions · 2026-07-25: 1Mentions · 2026-07-26: 1Mentions · 2026-07-27: 4Mentions · 2026-07-28: 3Mentions · 2026-07-29: 1Mentions · 2026-08-03: 3Mentions · 2026-08-31: 2Mentions · 2026-09-06: 1Mentions · 2026-09-11: 1Mentions · 2026-09-13: 1PoC Mentioned / Linked · 2026-06-26: 10PoC Mentioned / Linked · 2026-06-27: 5PoC Mentioned / Linked · 2026-06-28: 5PoC Mentioned / Linked · 2026-06-29: 4PoC Mentioned / Linked · 2026-06-30: 1PoC Mentioned / Linked · 2026-07-01: 1PoC Mentioned / Linked · 2026-07-02: 1PoC Mentioned / Linked · 2026-07-03: 1PoC Mentioned / Linked · 2026-07-04: 1PoC Mentioned / Linked · 2026-07-05: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-07-18: 1PoC Mentioned / Linked · 2026-07-22: 1PoC Mentioned / Linked · 2026-07-23: 1PoC Mentioned / Linked · 2026-07-25: 1PoC Mentioned / Linked · 2026-07-26: 1PoC Mentioned / Linked · 2026-07-27: 2PoC Mentioned / Linked · 2026-07-28: 1PoC Mentioned / Linked · 2026-08-03: 2PoC Mentioned / Linked · 2026-08-31: 1PoC Mentioned / Linked · 2026-09-13: 1Exploit Tool / Code · 2026-06-26: 6Exploit Tool / Code · 2026-06-27: 1Exploit Tool / Code · 2026-06-28: 3Exploit Tool / Code · 2026-06-29: 3Exploit Tool / Code · 2026-07-02: 1Exploit Tool / Code · 2026-07-06: 1Exploit Tool / Code · 2026-07-22: 1Exploit Tool / Code · 2026-07-26: 1Exploit Tool / Code · 2026-07-27: 1Exploit Tool / Code · 2026-08-03: 1Exploit Tool / Code · 2026-08-31: 1Active Exploitation · 2026-06-16: 1Active Exploitation · 2026-06-26: 1Active Exploitation · 2026-06-28: 1Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-07-27: 1Patch / Workaround · 2026-06-26: 6Patch / Workaround · 2026-06-27: 7Patch / Workaround · 2026-06-28: 5Patch / Workaround · 2026-06-29: 4Patch / Workaround · 2026-07-01: 2Patch / Workaround · 2026-07-18: 2Patch / Workaround · 2026-07-24: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 17Technical Details · 2026-06-27: 10Technical Details · 2026-06-28: 11Technical Details · 2026-06-29: 11Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 2Technical Details · 2026-07-04: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-12: 2Technical Details · 2026-07-18: 3Technical Details · 2026-07-22: 1Technical Details · 2026-07-23: 3Technical Details · 2026-07-24: 4Technical Details · 2026-07-25: 1Technical Details · 2026-07-26: 1Technical Details · 2026-07-27: 3Technical Details · 2026-07-28: 3Technical Details · 2026-07-29: 1Technical Details · 2026-08-03: 3Technical Details · 2026-08-31: 1Technical Details · 2026-09-11: 106-1606-2606-2907-0207-0507-1207-2307-2607-2909-0609-13
Signal classification6 categories
Disclosure
2926.1%
Patch
2219.8%
PoC
2219.8%
General
1917.1%
Exploit
1715.3%
Active Exploitation
21.8%
Referenced assets62 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-162
Active Exploitation1General1
2026-06-171
General1
2026-06-251
Disclosure1
2026-06-2622
Disclosure6Exploit5General1Patch5PoC5
2026-06-2714
Disclosure1Exploit2General5Patch5PoC1
2026-06-2812
Active Exploitation1Disclosure6Exploit1Patch3PoC1
2026-06-2913
Disclosure2Exploit2General3Patch4PoC2
2026-06-302
Exploit1General1
2026-07-013
General1Patch1PoC1
2026-07-022
Disclosure1Patch1
2026-07-032
Disclosure2
2026-07-042
Disclosure1PoC1
2026-07-051
PoC1
2026-07-061
Exploit1
2026-07-091
General1
2026-07-122
PoC2
2026-07-183
Patch2PoC1
2026-07-221
PoC1
2026-07-233
Disclosure2Exploit1
2026-07-245
Disclosure2General2Patch1
2026-07-251
PoC1
2026-07-261
PoC1
2026-07-274
Exploit2General1PoC1
2026-07-283
Disclosure2Exploit1
2026-07-291
Disclosure1
2026-08-033
Disclosure1PoC2
2026-08-312
Exploit1General1
2026-09-061
General1
2026-09-111
Disclosure1
2026-09-131
PoC1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Exploit

    🛑 A new #Linux kernel exploit (CVE-2026-46331) gets root without modifying a single file on disk. It poisons the cached copy of /bin/su in memory. The binary on disk stays untouched. File-integrity checks come back clean. The root shell is already open. Details here ↓ https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html

    Post summary

    The post announces a new Linux kernel exploit (CVE‑2026‑46331) that gains root by poisoning the in‑memory copy of /bin/su, producing an open root shell without altering disk files, with more details available via the provided link.

    22298301.4K686184.6K
    2.2M followersView on X
  • portbuster@portbuster1337
    Exploit

    Added 4 new LPE exploits to lpe-toolkit: - PEdit COW CVE-2026-46331 - DirtyClone CVE-2026-43503 - Bad Epoll CVE-2026-46242 - FUSE OOB CVE-2026-31694 https://github.com/portbuster1337/lpe-toolkit

    Post summary

    Four new local-privilege‑escalation exploit codes for CVE‑2026‑46331, 43503, 46242, and 31694 have been added to the lpe-toolkit repository, offering accessible PoC and exploit resources.

    465129519715.8K
    289 followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    🚨 Researchers say one short message let Claude Cowork escape its Linux VM and access files across the host Mac. The SharedRoot chain used CVE-2026-46331 to gain guest root, then crossed through Cowork’s read-write host mount. Read how it worked: https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html

    Post summary

    Researchers disclosed that a single message can let Claude Cowork escape its Linux VM using CVE-2026-46331, enabling it to read files from the host Mac.

    374427414561.0K
    2.3M followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CVE-2026-46331: A Linux kernel vulnerability affecting the act_pedit packet-editing component in the net/sched subsystem. CVSS: 7.8 Published: June 26th, 2026 PoC: https://github.com/0xBlackash/CVE-2026-46331 https://t.co/V8lbyakMvH

    Post summary

    A new Linux kernel vulnerability (CVE-2026-46331) affecting the act_pedit component in net/sched has been disclosed with CVSS 7.8, and a PoC is provided; no patches or active exploitation are reported.

    23421925921.8K
    231.8K followersView on X
  • ☠ Bluetouff@bluetouff
    Patch

    Une faille critique Linux « pedit COW » (CVE-2026-46331) permet à un utilisateur local non privilégié d’obtenir les droits root. Elle exploite une erreur dans l’action act_pedit du traffic-control (tc) qui corrompt la page-cache partagée au lieu d’effectuer une copie COW. L’attaquant empoisonne en mémoire un binaire setuid (/bin/su) sans modifier le disque : les vérifications d’intégrité restent propres. PoC public disponible. Affecte RHEL 8-10, Debian 11-13 et Ubuntu récents. Correctif publié ; mitigations : désactiver les user namespaces non privilégiés ou le module act_pedit. https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html

    Post summary

    A critical Linux local privilege escalation flaw (CVE-2026-46331) was disclosed with a public PoC; a patch has been released and mitigations are suggested.

    94101745013.3K
    40.4K followersView on X
  • elhacker.NET@elhackernet
    PoC

    Nuevo exploit de COW en Linux permite acceso root mediante el envenenamiento de binarios en caché Se ha descubierto una vulnerabilidad en el kernel de Linux (CVE-2026-46331) que permite a un usuario local sin privilegios obtener acceso root https://blog.elhacker.net/2026/06/nuevo-exploit-de-cow-en-linux-permite.html

    Post summary

    A Spanish blog post announces a new Linux kernel COW vulnerability (CVE‑2026‑46331) that can elevate local users to root through binary cache poisoning; the linked article likely contains a PoC, but no public exploit code, patch, or evidence of active exploitation is provided.

    0321122327.9K
    141.3K followersView on X
  • Rajat Gupta@z3ta_rjt
    PoC

    Introducing Dirty-Pedit (CVE-2026-46331)! A true semantic variant in the Dirty bug class: same page-cache corruption impact, but a completely different subsystem and a novel in-place writer. Two other syntactic variants that got collided: skb_shift and gro are in the repo. https://t.co/j4ICd8SpOS

    Post summary

    The tweet announces a new Dirty‑Pedit variant (CVE‑2026‑46331), noting its page‑cache corruption effect and pointing to a repository that contains proof‑of‑concept code.

    115181477.5K
    199 followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    PoC

    🐧 New Linux "pedit COW" Privilege Escalation Exploit Published Security researcher Massimiliano Oldani has released a public proof-of-concept (PoC) exploit, **packet_edit_meme**, for the Linux kernel vulnerability **CVE-2026-46331**, nicknamed **pedit COW**. * The flaw resides in Linux's **net/sched act_pedit** traffic control subsystem and allows an unprivileged local user to escalate privileges to **root** by corrupting shared page-cache memory. Public exploit code became available shortly after the CVE was assigned. [oai_citation:0‡The Hacker News](https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html) * The exploit abuses an out-of-bounds write caused by incorrect Copy-on-Write (COW) handling. By poisoning the page cache, attackers can modify cached privileged binaries in memory without directly altering the files on disk, making detection more challenging. [oai_citation:1‡The Hacker News](https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html) * The PoC repository: https://github.com/sgkdev/packet_edit_meme * Affected systems include numerous modern Linux distributions running vulnerable kernels. Multiple vendors, including Red Hat, Ubuntu, AlmaLinux, and CloudLinux, have already released or are rolling out patched kernels. [oai_citation:2‡TuxCare](https://tuxcare.com/blog/pedit-cow-cve/) Recommended actions: * Apply vendor kernel updates immediately and reboot where required. * Restrict unprivileged user namespaces where operationally feasible. * Monitor for unusual use of `tc` and `unshare`, which are commonly leveraged during exploitation. * Review systems for unexpected privilege escalation activity. [oai_citation:3‡http://blog.cloudlinux.com](https://blog.cloudlinux.com/pedit-cow-mitigation-and-kernel-update) Analyst Note: While this is **not a remote code execution vulnerability**, any environment where attackers can obtain local code execution (e.g., compromised web servers, containers, shared hosting, or developer workstations) should treat CVE-2026-46331 as a high-priority patch due to the availability of a reliable public exploit. #DDW #Intelligence #DarkWeb #Linux

    Post summary

    A public PoC exploit is available for the Linux kernel privilege‑escalation vulnerability CVE‑2026‑46331, and vendor patches have been released, with recommended mitigations for affected systems.

    1233892916.1K
    201.1K followersView on X
  • Tails@Tails_live
    Patch

    Tails 7.9.1 is out: https://tails.net/news/version_7.9.1/ It fixes CVE-2026-43503 (*DirtyClone*) and CVE-2026-46331 (*PACKET_EDIT_MEME*).

    Post summary

    Tails released version 7.9.1, which includes fixes for CVE‑2026‑43503 and CVE‑2026‑46331; no PoC, exploit, or active exploitation details are presented.

    3242104106.9K
    77.5K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    Linuxカーネルの権限昇格の脆弱性"Pedit COW" (CVE-2026-46331)について。6/16のCVE採番から24時間で既にPoC(攻撃の概念実証コード)が流通。tcf_pedit_act()から共有ページキャッシュを破壊可能。RHEL 10、Debian 13、Ubuntu 24.04(既定)でroot取得可能。 https://gbhackers.com/critical-linux-kernel-flaw-2/

    Post summary

    A privilege‑escalation flaw (CVE‑2026‑46331) in the Linux kernel has an available PoC within 24 hours, targeting RHEL 10, Debian 13, and Ubuntu 24.04 with root‑access potential.

    016051213.5K
    7.7K followersView on X
  • Pablo Fredrikson@PeladoNerd
    Disclosure

    Otro bug en el kernel de Linux: #peditCOW (CVE-2026-46331). El problema está en tc (traffic control) y un módulo que permite corromper el binario en memoria del page cache (muy parecido a #copyfail) https://tuxcare.com/blog/pedit-cow-cve/ https://t.co/wR53UsTWtS

    Post summary

    A new Linux kernel bug (CVE-2026-46331) in the traffic control subsystem can corrupt binaries in memory’s page cache, similar to the earlier copyfail flaw.

    27051164.7K
    33.1K followersView on X
  • Nicolas Krassas@Dinosn
    General

    Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/

    Post summary

    The text announces a sandbox escape via CVE‑2026‑46331 but provides no concrete PoC details, exploitation tools, or mitigation information.

    09040205.3K
    160.9K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    Patch

    Critical Linux Privilege Escalation: pedit COW Corrupts Page Cache to Hijack /bin/su in Memory Patch Immediately a reliable local root exploit for CVE-2026-46331 in Linux's act_pedit subsystem. Unprivileged users with namespaces enabled can poison cached binaries without touching disk files. Affects major distros; patches rolling out from Red Hat, Ubuntu & more. Update kernels & reboot ASAP, restrict user namespaces, and monitor tc/unshare. PoC - http://github.com/sgkdev/packet_edit_meme

    Post summary

    The excerpt announces CVE‑2026‑46331 as a local privilege escalation via pedit COW corruption, includes a PoC link, warns of major distro patches, and urges kernel updates.

    06026152.7K
    53.2K followersView on X
  • ɐpnH@AlAssaf_H
    Exploit

    CVE-2026-46331: Linux tcf_pedit_act() calculates the writable COW range before runtime typed-key offsets are known → part of the write lands outside the copied region → page-cache corruption. Public PoC reaches unprivileged local root: userns grants namespace-scoped CAP_NET_ADMIN, then act_pedit poisons the cached ELF image of a setuid-root binary and redirects execution to root shellcode. Trust boundary: unprivileged userns + namespace CAP_NET_ADMIN → host page cache / privileged executable. exploit: https://github.com/sgkdev/packet_edit_meme

    Post summary

    The post discloses a PoC and exploit code for CVE‑2026‑46331, detailing how unprivileged users can gain local root via page‑cache corruption, but there is no evidence of active exploitation or available patches.

    16016162.0K
    840 followersView on X
  • Ruben Groenewoud@RFGroenewoud
    PoC

    And another Linux LPE (CVE-2026-46331)... https://github.com/sgkdev/packet_edit_meme Existing Elastic EDR coverage: https://t.co/SWk4DH2Rjx

    Post summary

    The post highlights CVE‑2026‑46331, a Linux local privilege escalation vulnerability, and links to a GitHub repository that appears to contain a proof‑of‑concept exploit. No evidence of active exploitation, patching, or detailed technical information is provided.

    16020124.7K
    806 followersView on X
  • The CyberSec Guru@thecybersecguru
    Disclosure

    AI agents are becoming more capable, but are their sandboxes keeping up? Researchers have disclosed SharedRoot, a sandbox escape affecting Anthropic's Claude Cowork that lets an AI agent chain a Linux kernel privilege escalation (CVE-2026-46331) with a writable VirtioFS mount to access files across the host macOS system during local execution. Read the full technical analysis here 👇 https://thecybersecguru.com/news/claude-cowork-sharedroot-sandbox-escape-macos/

    Post summary

    Researchers disclosed a sandbox escape (CVE-2026-46331) in Anthropic's Claude Cowork that enables a Linux kernel privilege escalation via VirtioFS on macOS, with no active exploitation or patch information noted.

    320284217.3K
    1.5K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    The Linux pedit COW vulnerability (CVE-2026-46331) hands local users silent root via page cache poisoning, leaving no trace on disk. Patch now. #Linux #peditCOW #PrivilegeEscalation #LinuxKernel #CyberSecurity https://meterpreter.org/linux-pedit-cow-vulnerability/ https://t.co/5ILUK6Sc71

    Post summary

    The post announces CVE‑2026‑46331, a privilege‑escalation COW flaw that grants silent root to local users, and urges a patch. It does not provide exploit code, active exploitation evidence, or debunking.

    05053858
    12.9K followersView on X
  • ɐpnH@AlAssaf_H
    General

    Kernel advisory: https://kernel.googlesource.com/pub/scm/linux/security/vulns/+/143cc1d80fcbd962a17ccea5438f6c801a8274d8/cve/published/2026/CVE-2026-46331.json

    Post summary

    The post only references a kernel advisory URL for CVE‑2026‑46331, with no additional context or details.

    01074180
    840 followersView on X
  • NanoVMs@nanovms
    General

    you know what they say about containers and the page cache... CVE-2026-46331 https://t.co/ymeqQXLY6k

    Post summary

    The tweet merely references CVE-2026-46331 with a link, but provides no additional technical details or context.

    02082730
    2.2K followersView on X
  • /r/netsec@_r_netsec
    PoC

    Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/

    Post summary

    A blog post reports an escape from Claude Cowork's local VM sandbox using CVE‑2026‑46331, indicating a proof‑of‑concept exploit is demonstrated.

    000381.2K
    33.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.18--
OSlinuxlinux_kernel5.18--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more