CVE-2026-52933PoC(linux / linux_kernel)

HIGHCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath: if (unlikely(atomic_read(&req->poll_refs) >= IO_POLL_REF_BIAS)) atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG (BIT(31)) is set in poll_refs, the value becomes negative in signed arithmetic, so the >= 128 comparison always evaluates to false and the slowpath is never taken. Fix this by casting the atomic_read() result to unsigned int before the comparison, so that the cancel flag is treated as a large positive value and correctly triggers the slowpath.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 12 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 13 signals
  • General: 1 classified signal
  • Peaked 4d ago at 5 mentions (2026-08-31); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline13 mentions / 7d
01345Mentions · 2026-08-26: 3Mentions · 2026-08-27: 1Mentions · 2026-08-31: 5Mentions · 2026-09-01: 1Mentions · 2026-09-08: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-08-26: 3PoC Mentioned / Linked · 2026-08-27: 1PoC Mentioned / Linked · 2026-08-31: 5PoC Mentioned / Linked · 2026-09-01: 1PoC Mentioned / Linked · 2026-09-12: 1PoC Mentioned / Linked · 2026-09-15: 1Exploit Tool / Code · 2026-08-26: 3Exploit Tool / Code · 2026-08-27: 1Exploit Tool / Code · 2026-08-31: 4Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-31: 3Patch / Workaround · 2026-09-15: 1Technical Details · 2026-08-26: 3Technical Details · 2026-08-27: 1Technical Details · 2026-08-31: 5Technical Details · 2026-09-01: 1Technical Details · 2026-09-08: 1Technical Details · 2026-09-12: 1Technical Details · 2026-09-15: 108-2608-2708-3109-0109-0809-1209-15
Signal classification4 categories
PoC
969.2%
Exploit
215.4%
General
17.7%
Active Exploitation
17.7%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-08-263
Exploit1PoC2
2026-08-271
PoC1
2026-08-315
Exploit1PoC4
2026-09-011
PoC1
2026-09-081
General1
2026-09-121
Active Exploitation1
2026-09-151
PoC1
Full discourse13 posts
  • Nebula Security@nebusecurity
    Exploit

    Today's exploit is for the latest Fedora 44, a signedness in io_uring, CVE-2026-52933. It was introduced in Nov 2022 and fixed upstream in Apr 2026. Discovered and exploited by the NebuSec security pipeline (RANDOM_KMALLOC_CACHES + SELinux) EXP source: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52933-Fedora-6.19.10-300 https://t.co/cLbP0GyJDK

    Post summary

    The post announces a working exploit for CVE‑2026‑52933 on Fedora 44, provides a PoC via GitHub, notes an upstream fix, but does not report active attacks.

    214272255.9K
    6.9K followersView on X
  • yousukezan@yousukezan
    PoC

    Linuxカーネルのio_uringに、ローカル攻撃者が権限昇格できる脆弱性「CVE-2026-52933」が見つかり、動作するPoCも公開された。問題はio_poll_get_ownership()の符号付き比較にあり、複数のカーネル系列が影響を受ける。 公式アドバイザリによると、atomic_read()は符号付き整数を返し、IO_POLL_CANCEL_FLAGが有効になると値が負数となるため、slowpathへ入るためのしきい値比較が偽になる。これにより必要な処理が実行されず、攻撃者が資源管理の不整合を利用して権限を昇格できるという。 NebuSecはFedora 6.19.10-300向けのPoCを公開した。現時点で実際の悪用は確認されていない。修正はatomic_read()の結果を符号なし整数へキャストするもので、6.1.175、6.6.140、6.12.86、6.18.27、7.0.4などに取り込まれている。 影響する環境では最新カーネルへの更新が推奨され、直ちに更新できない場合はio_uring機能へのユーザーアクセス制限が緩和策として挙げられている。 https://securityonline.info/cve-2026-52933-privilege-escalation-poc/

    Post summary

    CVE-2026-52933 is a kernel privilege‑escalation flaw in io_uring, with a publicly available PoC and fix, but no active exploitation reported.

    010025123.0K
    15.0K followersView on X
  • Cyber Meowfia@cybermeowfia
    Exploit

    Aug 25: exploit for the latest Fedora 44, a signedness in io_uring, CVE-2026-52933. It was introduced in Nov 2022 and fixed upstream in Apr 2026. Discovered and exploited by the NebuSec security pipeline (RANDOM_KMALLOC_CACHES + SELinux) EXP source: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52933-Fedora-6.19.10-300 https://t.co/BqfljBUv9n

    Post summary

    The post announces an exploit for CVE-2026-52933, an io_uring signedness issue in Fedora 44, and links to the exploit source while noting an upstream fix.

    0102876.3K
    439 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Nebula Security, Fedora 44'te root yetkisi elde edilmesini sağlayan bir Linux kernel exploit'i yayınladı. CVE-2026-52933 olarak takip edilen açık, io_uring alt sistemindeki bir signedness hatasından kaynaklanıyor. Yayınlanan PoC, Fedora 44 / kernel 6.19.10-300.fc44 üzerinde yerel yetki yükseltme yoluyla root shell elde edilebildiğini gösteriyor. https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52933-Fedora-6.19.10-300 https://x.com/nebusecurity/status/2092431446824878130/video/1

    Post summary

    Nebula Security published a PoC that demonstrates a local privilege‑escape via an io_uring signedness flaw in Fedora 44 kernel 6.19.10‑300, identified as CVE‑2026‑52933, but there is no indication of active exploitation or patch availability.

    0601631.3K
    2.4K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-52933 Vendor: Linux Product: Linux kernel Description: An issue exists in the io poll get ownership() function where a signed comparison is used to determine if poll refs has reached the threshold for the slowpath. Because atomic read() returns a signed integer, setting the IO POLL CANCEL FLAG (BIT(31)) causes the value to be interpreted as negative. Consequently, the comparison against the threshold always evaluates to false, preventing the slowpath from being executed. Link: https://github.com/NebuSec/CyberMeowfia/blob/main/security-research/Linux-CVE-2026-52933-Fedora-6.19.10-300/exploit.c #dbugs_vuln

    Post summary

    A PoC exploit for CVE-2026-52933 is available on GitHub, highlighting a signed comparison flaw in the Linux kernel’s io poll get ownership() function that allows the IO POLL CANCEL FLAG to trigger a false negative comparison and bypass the slowpath.

    0401711.3K
    3.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    A public proof-of-concept for the CVE-2026-52933 privilege escalation flaw is available. This Linux kernel io_uring exploit carries a CVSS 7.8 score. #Linux #CVE202652933 #PrivilegeEscalation #KernelExploit #Cybersecurity https://securityonline.info/cve-2026-52933-privilege-escalation-poc/

    Post summary

    A public proof‑of‑concept for CVE‑2026‑52933 is available, detailing a Linux kernel io_uring privilege escalation flaw with a CVSS 7.8 score; no evidence of active exploitation or patching is mentioned.

    030113852
    12.9K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 HIGH: A public PoC for CVE-2026-52933 (CVSS 7.8) targets a Linux kernel io_uring privilege escalation flaw. The vulnerability stems from a signed integer comparison bug in io_poll_get_ownership(), potentially allowing a local low-privileged attacker to escalate privileges. 🔴 Linux systems should be updated to a patched kernel version immediately. 🔗 https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52933-Fedora-6.19.10-300 #Linux #Kernel #io_uring #CVE #PrivilegeEscalation #PoC #CyberSecurity #Infosec

    Post summary

    A public PoC for CVE-2026-52933 reveals a kernel privilege escalation flaw via io_uring; users are urged to upgrade to a patched kernel immediately.

    020732.2K
    1.5K followersView on X
  • Mr. OS@ksg93rd
    Active Exploitation

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    The text highlights several current vulnerabilities, including active exploitation of MikroTik RouterOS and sandbox escape in Claude Code, while providing CVE identifiers and linking to resources that likely contain PoC code but no detailed exploitation tools or patches.

    01052600
    3.4K followersView on X
  • Brad Spengler@spendergrsec
    General

    For oss-sec: CVE-2026-72137 needs xfrm, CVE-2026-52933 needs io_uring, CVE-2026-52929 needs sctp, CVE-2026-43502 needs rds (is what the original post was about)

    Post summary

    The text lists several CVEs with their required subsystems but provides no further details on PoC, exploits, patches, or active exploitation.

    00042767
    7.1K followersView on X
  • キタきつね@foxbook
    PoC

    Linuxカーネルの権限昇格脆弱性CVE-2026-52933に関する概念実証(PoC)が公開されました PoC Published for Linux Kernel Privilege Escalation CVE-2026-52933 Flaw #DailyCyberSecurity (Aug 31) https://securityonline.info/cve-2026-52933-privilege-escalation-poc/

    Post summary

    A proof‑of‑concept for the Linux kernel privilege escalation vulnerability CVE‑2026‑52933 has been publicly released, with a link to the PoC.

    02022606
    5.0K followersView on X
  • Threat Landscape@LandscapeThreat
    PoC

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    The text discloses a Linux kernel privilege escalation vulnerability (CVE-2026-43502) and notes that public exploits are available for it and other listed CVEs, while also providing details on the fix commit and affected versions.

    0002055
    109 followersView on X
  • P0KUS$@P0KUSS
    PoC

    Nebula Security, Fedora 44에서 루트 권한 획득을 가능하게 하는 리눅스 커널 익스플로잇을 공개했습니다. CVE-2026-52933으로 추적되는 이 취약점은 io_uring 하위 시스템의 signedness 오류에서 비롯됩니다. 공개된 PoC는 Fedora 44 / 커널 6.19.10-300.fc44에서 로컬 권한 상승을 통해 루트 셀을 획득할 수 있음을 보여줍니다. https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52933-Fedora-6.19.10-300 #보안

    Post summary

    Nebula Security released a PoC for CVE‑2026‑52933, demonstrating local privilege escalation on Fedora 44 via an io_uring signedness bug, and provided a code repository for the exploit.

    0001058
    5 followersView on X
  • moton@moton
    PoC

    CVSS 7.8 CVE-2026-52933 Privilege Escalation PoC Published - https://securityonline.info/cve-2026-52933-privilege-escalation-poc/

    Post summary

    An announced published PoC for CVE-2026-52933, a privilege escalation vulnerability rated CVSS 7.8, is provided with a link, but no mention of exploitation or remediation.

    0000095
    755 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.1--
OSlinuxlinux_kernel6.1--
OSlinuxlinux_kernel6.1--

Explore more