Red Hat released Important kernel security updates for multiple RHEL 8.6 and RHEL 9.0 service variants to address several Linux kernel flaws, including CVE-2026-46333, which lets an unprivileged local user read root-owned files. The bug stems from a race during process exit in kernels before commit 31e62c2ebbfd, where __ptrace_may_access() can skip a dumpable check when task->mm is NULL, allowing pidfd_getfd(2) to obtain file descriptors from a exiting process that still has accessible files. Qualys reported the issue, and Linus Torvalds merged the upstream fix in May 2026.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:24814, an Important security advisory for the kpatch-patch package covering RHEL 9.4 Extended Update Support and related service variants. The live patch update remediates CVE-2026-46333 without requiring a reboot and also addresses CVE-2026-46300.
Red Hat issued RHSA-2026:23469, an Important security advisory for kpatch live patch packages affecting RHEL 9.2 Update Services for SAP Solutions, AUS, and Extended Life Cycle offerings. The live patch update remediates CVE-2026-46333 along with CVE-2026-46300 across x86_64 and ppc64le package variants without requiring a kernel reboot.
Red Hat issued RHSA-2026:23471, an Important security advisory for kpatch live patch packages affecting RHEL 8.8 Update Services for SAP Solutions and related 8.8 offerings. The live patch update remediates CVE-2026-46333 along with CVE-2026-46300 across x86_64 and ppc64le package variants without requiring a kernel reboot.
Red Hat issued RHSA-2026:20129, an Important kernel security update for RHEL 9.6 Extended Update Support and related service channels. The advisory fixes CVE-2026-46333 along with CVE-2026-46300 across multiple architectures and instructs administrators to reboot after applying the update.
Red Hat issued RHSA-2026:20054, an Important kernel security update for RHEL 9.4 Extended Update Support and related 9.4 channels. The advisory fixes CVE-2026-46333 along with CVE-2026-46300 and instructs administrators to apply the update and reboot affected systems.
Red Hat issued RHSA-2026:20051, an Important kernel security update for RHEL 8.6 Advanced Mission Critical Update Support, Update Services for SAP Solutions, and Telecommunications Update Service. The advisory fixes CVE-2026-46333 and tells administrators to reboot affected systems after applying the update.
Red Hat issued RHSA-2026:19705, an Important kernel security update for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The advisory includes fixes for CVE-2026-46333 along with other kernel vulnerabilities and instructs administrators to reboot after installation.
Linus Torvalds fixed the Linux kernel flaw that lets an unprivileged user read root-owned files by exploiting a race during process exit. The Bugzilla entry states all stable kernels were affected as of that date prior to commit 31e62c2ebbfd.
The file-descriptor theft pattern underlying the later kernel issue was previously identified by Jann Horn in October 2020.
Red Hat's Bugzilla entry documents CVE-2026-46333 as a Linux kernel vulnerability that allows an unprivileged user to read root-owned files via pidfd_getfd during process exit. It credits Qualys with reporting the issue and notes multiple RHEL product variants were addressed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.