← All stories
● Covered by 1 source · 1 reportHigh impact

Linux pedit COW Exploit Allows Root Access via Cached Binary Poisoning

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CVE-2026-46331 exploits a flaw in Linux's traffic-control subsystem.
  • Unprivileged users can gain root access by corrupting cached binaries.
  • Debian 13 and RHEL systems affected; fixes vary by vendor.

Overview of the pedit COW Vulnerability

CVE-2026-46331, known as 'pedit COW', is a vulnerability in the Linux kernel's traffic-control subsystem that enables local unprivileged users to achieve root access. The flaw is an out-of-bounds write in the packet-editing action (act_pedit), which corrupts shared page-cache memory.

This exploit was made public within a day after its CVE assignment on June 16, 2026, prompting immediate attention from various Linux distributions.

Mechanism of Exploit

The exploit leverages the act_pedit function, which is designed to modify packet headers in real-time. Due to a flaw in the kernel's handling of memory copying during this process, the function can inadvertently alter a shared memory page instead of a private copy, corrupting the in-memory image of binaries such as /bin/su.

The exploit's prerequisites include having act_pedit being loadable and unprivileged user namespaces being enabled, which allows attackers to utilize necessary networking capabilities.

Affected Systems and Impact

Red Hat has classified the flaw as important, highlighting its potential to compromise systems. The proof of concept has been successfully tested on Red Hat Enterprise Linux (RHEL) 10 and Debian 13, where unprivileged user namespaces are enabled by default, thus exposing these systems to exploitation.

Notably, Ubuntu 24.04 and earlier versions can be compromised through specific conditions involving AppArmor profiles. Ubuntu 26.04 has implemented stricter controls that block this method, although the underlying kernel remains vulnerable.

Mitigation and Vendor Responses

Debian has issued patches via its security channel for Debian 13, while earlier versions remain at risk. Ubuntu has acknowledged the issue but notes that fixes will vary across different supported releases. This situation underscores ongoing vulnerabilities in widely used Linux distributions, necessitating immediate updates.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A critical flaw in the Linux kernel's traffic-control subsystem allows unprivileged users to gain root access on vulnerable systems. The exploit targets the memory cache of setuid binaries, enabling attackers to inject and execute malicious code while bypassing file integrity checks.