A high-severity Linux kernel local privilege escalation flaw, tracked as CVE-2026-46215, allowed unprivileged local users with access to a GPU DRM render node to gain passwordless root. The bug was a use-after-free race in DRM_IOCTL_GEM_CHANGE_HANDLE within the DRM GEM core, introduced in v6.18-rc1 during AMD CRIU checkpoint/restore work. Researchers showed the issue could be triggered by racing GEM_CHANGE_HANDLE against GEM_CLOSE, enabling concurrent handle manipulation and object freeing from interfaces reachable through render-node permissions.
Public exploit analysis and a GitHub proof of concept showed attackers could reclaim freed memory with pipe_buffer objects, leak a kernel pointer to bypass KASLR, set PIPE_BUF_FLAG_CAN_MERGE to sidestep the Dirty Pipe mitigation, and overwrite /etc/passwd through the page cache to remove the root password. The exploit reportedly succeeded on 99 of 100 test boots with fewer than 100 race attempts on average. The vulnerability was credited to Puttimet Thammasaeng and fixed in Linux 6.18.32, 7.0.9, and 7.1-rc3, while maintainers also moved to disable the GEM_CHANGE_HANDLE ioctl in the upcoming 7.1 release because of this and related race conditions.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
The vulnerability was fixed in Linux versions 6.18.32, 7.0.9, and 7.1-rc3, and maintainers also disabled the GEM_CHANGE_HANDLE ioctl in the upcoming 7.1 release because of this and related races.
The flaw was first reported by Puttimet Thammasaeng, who received the official CVE credit and upstream reported-by attribution for the Linux kernel local privilege escalation issue.
The vulnerability CVE-2026-46215 was introduced in Linux kernel v6.18-rc1 as part of AMD CRIU checkpoint/restore work, creating a use-after-free race in DRM_IOCTL_GEM_CHANGE_HANDLE reachable via render nodes.
A public GitHub repository documented exploit analysis and proof-of-concept code for CVE-2026-46215, showing how an unprivileged user with render node access could gain passwordless root on vulnerable kernels.
Ubuntu published a CVE tracking page for CVE-2026-46215, indicating downstream vendor tracking of the Linux kernel vulnerability.
A Linux kernel commit updated drm_gem_change_handle_ioctl to use safer IDR allocation and replacement logic while holding the relevant locks, preventing incorrect object mapping during GEM handle changes. The patch reflects an upstream code-level fix or hardening step for the race condition later tracked as CVE-2026-46215.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
11 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcegithub.com
Open sourcecyberstan.co.uk
Open sourcebugzilla.redhat.com
Open sourcegit.kernel.org
Open sourcegit.kernel.org
Open sourcesecurity-tracker.debian.org
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.