Linux Kernel Flaws Expose Systems to Local Root Escalation
Researchers disclosed two separate Linux kernel privilege-escalation flaws that can give local attackers root access across a wide range of systems, including servers, desktops, and Android devices. One bug, CVE-2026-46242 or Bad Epoll, is a use-after-free race in the kernel's epoll subsystem that was reportedly exploited through Google's kernelCTF program and shown to be broadly reachable because epoll is a core component that cannot be disabled. The flaw was introduced by a 2023 kernel change, and reporting said an initial patch attempt was insufficient before a correct fix was merged weeks later, leaving defenders dependent on upstream fixes and vendor backports. A second flaw, CVE-2026-43456, affects the kernel's net/bonding subsystem and stems from a type-confusion condition dating back to 2007. Researchers said the bug can be exploited with high reliability for local root by abusing incompatible headerops handling in bonded network devices, enabling controlled memory corruption and eventual code execution. The issue reportedly affects Linux versions 2.6.24 through 6.12.77 and requires CAPNET_ADMIN privileges; mitigations include applying the March 2026 patch, or temporarily disabling unprivileged user namespaces or the bonding module where feasible.. Fonte: https://mallory.ai/stories/019f2b1a-8651-7e8a-bbe4-9bb9f7ce315c
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.