<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Local file exposure #vulnerability in linux kernels (CVE-2026-46333):]]></title><description><![CDATA[<p>Local file exposure <a href="https://infosec.exchange/tags/vulnerability" rel="tag">#<span>vulnerability</span></a> in linux kernels (CVE-2026-46333):</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn" title="GitHub - 0xdeadbeefnetwork/ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.">
<img src="https://opengraph.githubassets.com/d632ecee7bdd0c84441c62cafc332d7626eb34a0ff52a90b2f5604dec7fb8bd2/0xdeadbeefnetwork/ssh-keysign-pwn" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn">
GitHub - 0xdeadbeefnetwork/ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.
</a>
</h5>
<p class="card-text line-clamp-3">Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels. - 0xdeadbeefnetwork/ssh-keysign-pwn</p>
</div>
<a href="https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://github.githubassets.com/favicons/favicon.svg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0">GitHub <span class="text-secondary">(github.com)</span></p>
</a>
</div><p></p><p>Apparently this issue was already identified in 2020 but wasn't fixed back then.</p><p>Mitigation:<br />- runtime:<br />sudo sysctl -w kernel.yama.ptrace_scope=2<br />- To make the migiration persistent:<br />echo "kernel.yama.ptrace_scope=2" | sudo tee /etc/sysctl.d/01-harden-ptrace.conf</p><p>WARNING: This migation may break existing functionality. Test before deploying.</p><p>WARNING  2: While this mitigation does block the currently existing PoC, it may not prevent other attack vectors exploiting this vulnerability.</p><p><a href="https://infosec.exchange/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/CVE_2026_46333" rel="tag">#<span>CVE_2026_46333</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/f189da7d-1fb7-4a6b-91f2-77199f1a678f/local-file-exposure-vulnerability-in-linux-kernels-cve-2026-46333</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 15:41:45 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/f189da7d-1fb7-4a6b-91f2-77199f1a678f.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 15 May 2026 08:27:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Local file exposure #vulnerability in linux kernels (CVE-2026-46333): on Fri, 15 May 2026 19:19:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/harrysintonen%40infosec.exchange">@<span>harrysintonen</span></a></span> That must have dropped in the last four hours or so. Thanks! Updating now.</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/knasman/statuses/116580207237335253</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/knasman/statuses/116580207237335253</guid><dc:creator><![CDATA[knasman@fosstodon.org]]></dc:creator><pubDate>Fri, 15 May 2026 19:19:51 GMT</pubDate></item><item><title><![CDATA[Reply to Local file exposure #vulnerability in linux kernels (CVE-2026-46333): on Fri, 15 May 2026 18:57:54 GMT]]></title><description><![CDATA[<p><a href="https://infosec.exchange/tags/Debian" rel="tag">#<span>Debian</span></a> has released kernel update that fixes this vulnerability.</p><p>Debian stable (trixie) kernel update: <a href="https://lists.debian.org/debian-security-announce/2026/msg00185.html" rel="nofollow noopener"><span>https://</span><span>lists.debian.org/debian-securi</span><span>ty-announce/2026/msg00185.html</span></a></p><p>Debian oldstable (bookworm) kernel update: <a href="https://lists.debian.org/debian-security-announce/2026/msg00186.html" rel="nofollow noopener"><span>https://</span><span>lists.debian.org/debian-securi</span><span>ty-announce/2026/msg00186.html</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/harrysintonen/statuses/116580120971058461</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/harrysintonen/statuses/116580120971058461</guid><dc:creator><![CDATA[harrysintonen@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 18:57:54 GMT</pubDate></item><item><title><![CDATA[Reply to Local file exposure #vulnerability in linux kernels (CVE-2026-46333): on Fri, 15 May 2026 08:29:42 GMT]]></title><description><![CDATA[<p>kernel.yama.ptrace_scope = 2: Only admin can use ptrace, as it required CAP_SYS_PTRACE capability.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/harrysintonen/statuses/116577650780691530</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/harrysintonen/statuses/116577650780691530</guid><dc:creator><![CDATA[harrysintonen@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 08:29:42 GMT</pubDate></item></channel></rss>