CVE-2026-46333 - "ssh-keysign-pwn" Linux Kernel Privilege Escalation

CVE-2026-46333 Linux Kernel Privilege Escalation Local Root
Overview
A Linux kernel vulnerability tracked as CVE-2026-46333 allows local attackers to escalate privileges to root. The flaw reportedly existed for approximately nine years and affects multiple major Linux distributions.
Researchers demonstrated successful exploitation against modern Ubuntu and Debian systems.
Technical Specifications
| Attribute | Details |
|---|---|
| CVE | CVE-2026-46333 |
| Nickname | ssh-keysign-pwn |
| Vulnerability Class | Local privilege escalation (LPE) |
| Affected Logic | Linux kernel __ptrace_may_access() privilege-checking path |
| Exploit Condition | Credential-transition and shutdown edge-case handling abuse |
| Abused Target Process (Reported) | Privileged process interaction such as ssh-keysign |
| Result | Unauthorized sensitive memory access and escalation to root |
| Affected Timeline | Kernel lineage reportedly vulnerable since 2016 |
| PoC Status | Qualys proof-of-concept exploits reported for Debian 13 and Ubuntu 24.04/26.04 |

Affected Products
- Linux distributions using vulnerable kernel builds dating back to 2016-era code paths
- Ubuntu systems (reported PoC targets include 24.04 and 26.04)
- Debian systems (reported PoC target includes Debian 13)
- Multi-tenant and cloud workloads where local footholds are possible
Attack Scenario
-
Initial Foothold: The attacker gains low-privileged local access through stolen credentials, web-shell access, container compromise, or another vulnerability.
-
Local Exploit Execution: Exploit code is executed to target vulnerable kernel privilege-checking behavior.
-
ptrace Logic Abuse: The exploit abuses
ptracepermission handling involving privileged processes such asssh-keysign. -
Privilege Escalation: The attacker elevates privileges to root.
-
Post-Compromise Control: Full system compromise enables persistence, credential theft, and lateral movement.
Impact Assessment
- Full root compromise of Linux systems
- Security control tampering or disablement
- Persistence installation by local threat actors
- Theft of SSH keys and credential material
- Broader account abuse and trust-boundary compromise
- Elevated risk for cloud workloads and shared hosting
- Potential container-to-host escalation scenarios
Mitigation Strategies
Patch and Hardening
- Apply vendor kernel patches immediately.
- Update affected Linux distributions to patched kernel versions.
- Restrict ptrace functionality with
kernel.yama.ptrace_scope = 2where operationally feasible.
Detection and Response
- Monitor for abnormal
ptraceusage or suspiciousssh-keysignactivity. - Audit systems for indicators of unauthorized privilege escalation.
- Rotate credentials and SSH keys if compromise is suspected.
- Enforce least-privilege access controls across interactive and service accounts.
Resources and References
Open-Source Reporting
Last Updated: May 24, 2026