PT-2026-49625 · Linux+4 · Linux Kernel+4

·

CVE-2026-46331

·

Published

2026-05-18

·

Updated

2026-09-11

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds write flaw exists in the act pedit (packet-editing action) of the Linux kernel traffic-control subsystem. The function tcf pedit act() incorrectly computes the Copy-on-Write (COW) range for skb ensure writable() by using tcfp off max hint, which fails to account for runtime header offsets added by typed keys. This allows part of the write region to remain un-COW'd, leading to the corruption of shared page-cache memory. A local unprivileged attacker can exploit this to poison cached privileged binaries in memory, such as /bin/su, without altering the files on disk, enabling local privilege escalation to root or causing a system crash. This issue is particularly exploitable in environments where unprivileged user namespaces are enabled, as they can grant namespace-scoped CAP NET ADMIN privileges.
Recommendations Apply vendor kernel updates immediately and reboot the system. Restrict the use of unprivileged user namespaces where operationally feasible. Monitor for unusual use of tc and unshare commands. Review systems for unexpected privilege escalation activity.

Exploit

Fix

LPE

DoS

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:27288
ALSA-2026:27353
ALSA-2026:27354
ALSA-2026:27789
AZL-90107
BDU:2026-08426
CVE-2026-46331
ECHO-170F-91A6-557D
OESA-2026-2751
OESA-2026-2752
OESA-2026-2754
OESA-2026-2870
OPENSUSE-SU-2026:21388-1
RHSA-2026:27288
RHSA-2026:27353
RHSA-2026:27354
RHSA-2026:27355
RHSA-2026:27704
RHSA-2026:27705
RHSA-2026:27706
RHSA-2026:27707
RHSA-2026:27708
RHSA-2026:27709
RHSA-2026:27713
RHSA-2026:27731
RHSA-2026:27789
RHSA-2026:33219
RHSA-2026:33220
RHSA-2026:33221
RHSA-2026:33222
RHSA-2026:33223
RHSA-2026:33224
RHSA-2026:33225
RHSA-2026:33666
SUSE-SU-2026:2195-1
SUSE-SU-2026:2238-1
SUSE-SU-2026:22521-1
SUSE-SU-2026:22522-1
SUSE-SU-2026:22665-1
SUSE-SU-2026:22666-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1
SUSE-SU-2026:2839-1
SUSE-SU-2026:2840-1
SUSE-SU-2026:2841-1
SUSE-SU-2026:2914-1
SUSE-SU-2026:3044-1
SUSE-SU-2026:3089-1
SUSE-SU-2026:3156-1
SUSE-SU-2026:3702-1
SUSE-SU-2026:3703-1
SUSE-SU-2026:3706-1
SUSE-SU-2026:3707-1
SUSE-SU-2026:3708-1
SUSE-SU-2026:3709-1
SUSE-SU-2026:3710-1
SUSE-SU-2026:3715-1
SUSE-SU-2026:3717-1
SUSE-SU-2026:3721-1
SUSE-SU-2026:3722-1
SUSE-SU-2026:3723-1
SUSE-SU-2026:3724-1
SUSE-SU-2026:3728-1
SUSE-SU-2026:3729-1
SUSE-SU-2026:3734-1
SUSE-SU-2026:3739-1
SUSE-SU-2026:3740-1
SUSE-SU-2026:3743-1
SUSE-SU-2026:3744-1
SUSE-SU-2026:3747-1
SUSE-SU-2026:3749-1
SUSE-SU-2026:3750-1
SUSE-SU-2026:3756-1
SUSE-SU-2026:3757-1
SUSE-SU-2026:3759-1
SUSE-SU-2026:3766-1
SUSE-SU-2026:3808-1
SUSE-SU-2026:3826-1
USN-8629-1
USN-8629-2
USN-8629-3
USN-8630-1
USN-8630-2
USN-8630-3
USN-8630-4
USN-8630-5
USN-8631-1
USN-8631-2
USN-8631-3
USN-8631-4
USN-8633-1
USN-8633-2
USN-8635-1
USN-8636-1
USN-8636-2
USN-8637-1
USN-8645-1
USN-8656-1
USN-8660-1
USN-8661-1
USN-8661-2
USN-8661-3
USN-8661-4
USN-8663-1
USN-8664-1
USN-8666-1
USN-8666-2
USN-8666-3
USN-8667-1
USN-8669-1
USN-8715-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Rocky Linux
Ubuntu