CVE-2026-46333
Modified
Modified - Updated After Analysis
BaseFortify
Vulnerability report for CVE-2026-46333, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-05-15
Last updated on: 2026-07-15
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
ptrace: slightly saner 'get_dumpable()' logic
The 'dumpability' of a task is fundamentally about the memory image of
the task - the concept comes from whether it can core dump or not - and
makes no sense when you don't have an associated mm.
And almost all users do in fact use it only for the case where the task
has a mm pointer.
But we have one odd special case: ptrace_may_access() uses 'dumpable' to
check various other things entirely independently of the MM (typically
explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for
threads that no longer have a VM (and maybe never did, like most kernel
threads).
It's not what this flag was designed for, but it is what it is.
The ptrace code does check that the uid/gid matches, so you do have to
be uid-0 to see kernel thread details, but this means that the
traditional "drop capabilities" model doesn't make any difference for
this all.
Make it all make a *bit* more sense by saying that if you don't have a
MM pointer, we'll use a cached "last dumpability" flag if the thread
ever had a MM (it will be zero for kernel threads since it is never
set), and require a proper CAP_SYS_PTRACE capability to override.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | From 4.8.16 (inc) to 4.9 (exc) |
| linux | linux_kernel | From 4.4.40 (inc) to 4.5 (exc) |
| linux | linux_kernel | 7.1 |
| linux | linux_kernel | 7.1 |
| linux | linux_kernel | From 3.16.52 (inc) to 3.17 (exc) |
| linux | linux_kernel | 7.1 |
| linux | linux_kernel | From 5.11 (inc) to 5.15.207 (exc) |
| linux | linux_kernel | From 5.16 (inc) to 6.1.173 (exc) |
| linux | linux_kernel | From 6.2 (inc) to 6.6.139 (exc) |
| linux | linux_kernel | From 4.9.1 (inc) to 5.10.256 (exc) |
| linux | linux_kernel | From 6.13 (inc) to 6.18.31 (exc) |
| linux | linux_kernel | From 6.19 (inc) to 7.0.8 (exc) |
| linux | linux_kernel | From 6.7 (inc) to 6.12.89 (exc) |
| debian | debian_linux | 11.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |