A use-after-free race in the Linux kernel's epoll subsystem, tracked as CVE-2026-46242 and dubbed Bad Epoll, allows an unprivileged local user to escalate to root and may also be reachable from constrained environments including the Chrome renderer sandbox and potentially Android. The bug was introduced in 2023 in fs/eventpoll.c, stems from a race in ep_remove() and ep_remove_file() during concurrent close operations on related epoll file objects, and was reported by Jaeyoung Chung of Seoul National University as a 0-day submission to Google's kernelCTF. Public reporting says the exploit achieves roughly 99% reliability on some targets despite a narrow race window, making it unusually dangerous for a modern Linux local privilege-escalation flaw.
Researchers and vendors said there is no practical workaround because epoll is a core kernel feature, and fixes were issued through upstream and backported updates including 6.6.144+ and 6.12.95+, with advisories for distributions such as Debian trixie, RHEL 9, RHEL 10, and Azure Linux 3. The disclosures also tied the issue to a broader pattern of advanced exploit discovery in kernel and browser-adjacent code: Google Project Zero previously highlighted renderer-to-kernel exploitation paths using MSG_OOB, while Anthropic said its Mythos Preview system found a separate epoll race, CVE-2026-43074, in the same area of code. Maintainers noted that fixing that earlier epoll bug did not eliminate Bad Epoll, underscoring how difficult this code path has been to secure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-11, Codeby published a technical breakdown of CVE-2026-46242 covering the race condition, exploit reliability, affected kernel branches, and patched versions. The article also noted enterprise distribution advisories and backported fixes.
Jaeyoung Chung of Seoul National University Computer Security Lab reported CVE-2026-46242 and submitted it as a 0-day to Google's kernelCTF, along with a highly reliable local privilege escalation exploit. The reporting described the bug as potentially reachable from Chrome's renderer sandbox and relevant to Android rooting scenarios.
The Bad Epoll vulnerability was fixed in April 2026 by commit a6dc643c6931. Later patched kernel lines included 6.6.144+ and 6.12.95+, with downstream vendors issuing advisories or backports.
The use-after-free race behind CVE-2026-46242 was introduced by commit 58c9b016e128 in 2023, creating a local privilege escalation flaw in the epoll subsystem.
On 2026-04-07, Anthropic announced Claude Mythos Preview and Project Glasswing, saying the model could autonomously find and exploit zero-day vulnerabilities across major software targets. The company said it was withholding most technical details because more than 99% of the findings remained unpatched.
On 2026-07-08, an oss-security post publicly described CVE-2026-46242 ('Bad Epoll') as a Linux local privilege escalation vulnerability affecting Linux and potentially Android. The disclosure highlighted the lack of a practical workaround and contrasted the bug with the related epoll race CVE-2026-43074.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcered.anthropic.com
Open sourceprojectzero.google
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.