A critical privilege escalation vulnerability in the Linux kernel’s traffic control subsystem, tracked as CVE-2026-46331 and dubbed “Pedit COW,” allows any unprivileged local user to gain root access on affected systems. The flaw resides in the tcf_pedit_act() function, where an out-of-bounds write during a copy-on-write operation corrupts shared page cache memory because the kernel fails to account for runtime header offsets added by typed keys.
A public working exploit called “packet_edit_meme” appeared within a day of the CVE assignment on June 16. The exploit poisons the cached copy of a setuid root binary like /bin/su in memory, injects a payload, and executes the altered image as root — critically, without modifying the on-disk file, which means traditional file integrity checks are bypassed entirely. Exploitation requires CAP_NET_ADMIN, obtainable through unprivileged user namespaces enabled by default on Red Hat, Debian, and Ubuntu.
Affected systems include RHEL 8, 9, and 10, and all supported Ubuntu releases from 18.04 through 26.04. Mitigation involves applying the upstream kernel patch or blocking the act_pedit module to prevent automatic loading.
Sources
- The Hacker News — New Linux Pedit COW Exploit Enables Root Privilege Escalation
- Red Hat CVE-2026-46331 Advisory
- GBHackers — Critical Linux Kernel Flaw
Commentary
Pedit COW is a nasty one. The page cache corruption technique is elegant from an offensive perspective — poisoning in-memory copies of setuid binaries without touching disk means you’re invisible to most integrity monitoring. It’s reminiscent of Dirty COW (CVE-2016-5195) but hits a different subsystem and bypasses a different set of assumptions.
The real concern here is the attack surface: unprivileged user namespaces are enabled by default on most enterprise Linux distributions, meaning the CAP_NET_ADMIN requirement is effectively no barrier at all for local attackers. If you run Linux in production and haven’t patched yet, this should be at the top of your priority list. A public weaponized exploit within 24 hours of CVE assignment leaves zero room for delay.
