TGViewer
Fsecurity | HH Fsecurity | HH @hellohackingteam · 2.06K subscribers
Post #7690 126

Forwarded from APT

ssh-keysign-pwn — CVE-2026-46333

A critical race condition flaw in pre-31e62c2ebbfd Linux kernels. Due to a window during process exit where the memory management structure is cleared before file descriptors are closed, an unprivileged user can use pidfd_getfd(2) to steal open file descriptors of privileged processes, enabling unauthorized reading of root-owned files.

🔗 Exploit:
https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn

🔗 Source:
https://blog.qualys.com/vulnerabilities-threat-research/2026/05/20/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path

#linux #kernel #privesc #racecondition #pidfd
GitHub GitHub - 0xdeadbeefnetwork/ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass… Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels. - 0xdeadbeefnetwork/ssh-keysign-pwn
More from @hellohackingteam
  1. Oct 9, 2026🔑 SrHollow - дамп LSA secrets без касания к LSASS Очередной дампер секретов Windows, но с…
  2. Oct 9, 2026Глобальная панель разведки в реальном времени, которая агрегирует отслеживание полетов в р…
  3. Oct 9, 2026Discord сервер 👆🏻Тут можно пообщаться и найти много полезной информации 🦈
  4. Oct 9, 2026Собрал GitLab видео PoC's 🔍 При ресерче различных CVE под GitLab появилась необходимость…
  5. Oct 9, 2026🔗 Ссылка: https://github.com/Casualtek/Ransomchats
  6. Oct 8, 2026🔗 Ссылка: https://codeby.net/threads/analiz-kiberintsidentov-v-rossii-2025-proval-signatu…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →