The images in this article were generated with artificial intelligence. How we publish
The security community has discovered a deep root vulnerability in the Linux kernel that passed unnoticed for nine years and now receives the label CVE-2026-46333, also known in some reports as ssh-keysign-pwn. The default, introduced in 2016 in the _ _ ptrace _ may _ access () function, allows a local user without privileges to access sensitive files and, in real scenarios, to raise privileges to get root in default facilities of popular distributions such as Debian, Fedora and Ubuntu.
From a technical point of view, the problem is a failure in the management of ptrace permits, the mechanism that allows one process to examine or manipulate another. Ptrace was designed for debugging, but its incorrect validation can become a reliable path to root as the researchers describe. The reported operation allows both the reading of / etc / shadow and private SSH keys and the arbitrary execution as root by means of vectors that abuse set-UID binary as chage, ssh-keysign, pkexec and accounts-daemon.

The finding highlights a recurring lesson: small pieces of the kernel that interact with user mechanisms, such as ptrace or communication channels between processes, are often risk surface for years. In this particular case, vulnerability was exploitable in default systems and there was publication of a proof-of-concept shortly after a related public commission appeared, which increases the exposure window for unanticipated administrators.
The practical implications for operations and security are direct and urgent. If a host allowed access to unreliable users during the exposure period, local credentials and SSH host keys should be considered compromised. The immediate steps include applying the kernel patches provided by the distributions, rotating the SSH host keys and any administrative credential that may have resided in the memory of set-UID processes.
When it is not possible to apply updates immediately, there is a temporary mitigation that changes the ptrace scope: raising the value of kernel. It is a useful containment measure, but it does not replace the updating of the kernel or the complete review of credentials in the system concerned.
In addition to reactive actions, it is appropriate to strengthen preventive practices: reduce the number of local users with unprivileged access, audit and minimize default set-UID binaries, and disable unnecessary modules such as RDS or io _ uring if not required by the workload. Remember that other recent kernel failures have shown similar vectors (e.g., exploits that depend on RDS or io _ uring) and that mitigating unused modules is a measure of low cost and high benefit.

For response equipment and critical infrastructure, in addition to rotating keys, it is recommended to review authentication and syscalls, and use forensic tools to detect local operating devices. If intrusion prior to mitigation is suspected, the safest option is to rebuild critical systems and validate integrity from trusted images; reversing only patches may not be enough if credentials have been exfiltered.
This vulnerability also forces industry and administrators to think of maintenance cycles and kernel patches as part of basic hygiene: do not leave systems without updating for years or blindly rely on the implicit security of default distributions. To deepen how ptrace works and why it is a recurring vector, the official kernel documentation offers useful technical context: Ptrace documentation in kernel. For vulnerability monitoring and warnings, see safety warning sources and CVE databases: NVD - National Vulnerability Database and research notes from suppliers such as Qualys: Qualys Research.
In short, act now: apply kernel updates when available, implement ptrace temporary mitigation if you need time to park, key rote and local credentials if there was unreliable access, and take the opportunity to reduce the attack surface by removing binaries and unnecessary modules. The pattern is repeated: subtle errors in process interaction mechanisms can remain latent years and, when they are exploited, their impact is immediate and profound.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...