Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-46333

7.1 · HIGH
Published May 15, 2026 linux CWE-269

Overview

CVE-2026-46333 is a high-severity vulnerability affecting linux linux_kernel. It was published on May 15, 2026 and has a CVSS 3.1 base score of 7.1 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ptrace: slightly saner 'get_dumpable()' logic

The 'dumpability' of a task is fundamentally about the memory image of

the task - the concept comes from whether it can core dump or not - and

makes no sense when you don't have an associated mm.

And almost all users do in fact use it only for the case where the task

has a mm pointer.

But we have one odd special case: ptrace_may_access() uses 'dumpable' to

check various other things entirely independently of the MM (typically

explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for

threads that no longer have a VM (and maybe never did, like most kernel

threads).

It's not what this flag was designed for, but it is what it is.

The ptrace code does check that the uid/gid matches, so you do have to

be uid-0 to see kernel thread details, but this means that the

traditional "drop capabilities" model doesn't make any difference for

this all.

Make it all make a

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 3.16.52, < 3.17 Affected

Frequently Asked Questions

What is CVE-2026-46333?

CVE-2026-46333 is a high-severity vulnerability affecting linux linux_kernel. It was published on May 15, 2026 and has a CVSS 3.1 base score of 7.1 (HIGH).

How severe is CVE-2026-46333?

This vulnerability has a CVSS 3.1 base score of 7.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-46333?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-46333?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-46333 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.