Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-46331 — CVE-2026-46331 | Kitploit
Tools/GitHubGitHub/0xblackash/cve-2026-46331
Privilege EscalationMemory ForensicsVulnerability AnalysisExploitationLearning & EducationBinary Exploitation
GitHub0xblackash/cve-2026-46331

CVE-2026-46331

CVE-2026-46331

View Repository
29593 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 CVE-2026-46331 - Linux Kernel COW Bug

ChatGPT Image Jun 26, 2026, 08_01_34 PM

Linux Kernel net/sched Partial Copy-on-Write (COW) Page Cache Corruption

Platform Severity Component Status

A Linux kernel vulnerability caused by incorrect Copy-on-Write (COW) handling in the traffic control (tc) packet editing subsystem.


📖 Overview

CVE-2026-46331 is a Linux kernel vulnerability affecting the net/sched packet editing (act_pedit) subsystem.

The vulnerability occurs because the kernel calculates the writable Copy-on-Write (COW) range before the actual packet-edit offset is known. When runtime header offsets are applied, portions of memory may remain writable without being copied, resulting in page cache corruption.

Under specific conditions, this corruption can become a powerful primitive for local privilege escalation (LPE) or kernel instability. :contentReference[oaicite:0]{index=0}


🔍 Technical Details

Vulnerable Component

Linux Kernel
└── net/
    └── sched/
        └── act_pedit.c

Affected function:

tcf_pedit_act()

Problem:

skb_ensure_writable()
        │
        ▼
Calculates writable range only once
        │
        ▼
Runtime header offsets change later
        │
        ▼
Memory outside COW region is modified
        │
        ▼
Page Cache Corruption

💥 Root Cause

The vulnerable implementation:

  • Computes the writable region only once.
  • Uses tcfp_off_max_hint.
  • Does not account for runtime offsets introduced by typed packet-edit keys.
  • Writes beyond the copied region.

This creates a partial Copy-on-Write condition that can corrupt cached kernel pages. :contentReference[oaicite:1]{index=1}


⚠️ Impact

Possible consequences include:

  • Kernel memory corruption
  • Page cache corruption
  • System crashes
  • Undefined kernel behavior
  • Potential Local Privilege Escalation (LPE)
  • Privileged code execution under favorable conditions :contentReference[oaicite:2]{index=2}

🎯 Attack Requirements

An attacker generally requires:

  • Local code execution
  • Ability to configure Linux Traffic Control (tc)
  • CAP_NET_ADMIN (directly or through an unprivileged user namespace, depending on system configuration)

No remote attack vector has been described in the official advisory. :contentReference[oaicite:3]{index=3}


📸 Demo

CVE-2026-46331

📦 Affected Component

Traffic Control (tc)

        │

 act_pedit

        │

 tcf_pedit_act()

        │

 skb_ensure_writable()

        │

 Partial COW

        │

 Page Cache Corruption

🛠 Fix

The upstream kernel patch:

  • Moves skb_ensure_writable() inside the per-key processing loop.
  • Uses the actual runtime write offset.
  • Adds integer overflow validation.
  • Uses skb_cow() for negative offsets.
  • Prevents invalid offset arithmetic (INT_MIN). :contentReference[oaicite:4]{index=4}

🛡 Mitigation

  • ✅ Update to a patched Linux kernel.
  • ✅ Restrict CAP_NET_ADMIN.
  • ✅ Disable unnecessary tc packet-edit rules.
  • ✅ Limit unprivileged user namespaces where operationally appropriate.
  • ✅ Reboot after installing the fixed kernel. :contentReference[oaicite:5]{index=5}

📊 Summary

FieldValue
CVECVE-2026-46331
ComponentLinux Kernel net/sched
Moduleact_pedit
VulnerabilityPartial Copy-on-Write
ImpactPage Cache Corruption
Possible ResultKernel Memory Corruption / Potential LPE
Attack VectorLocal
Privileges RequiredTypically CAP_NET_ADMIN
Fix Available✅ Yes

📚 References

  • NIST National Vulnerability Database :contentReference[oaicite:6]{index=6}
  • Red Hat Security Advisory :contentReference[oaicite:7]{index=7}
  • Ubuntu Security Notice :contentReference[oaicite:8]{index=8}

⭐ Stay Updated

Kernel vulnerabilities evolve rapidly.

Always keep your Linux kernel updated with the latest stable security patches.

Download Tool