Description:
The elevation of privilege vulnerability (PinTheft, CVE-2026-43494) and information disclosure vulnerability (CVE-2026-46333) are found in the Linux kernel. A local unprivileged attacker may leverage the vulnerabilities to escalate their privilege to root or disclose sensitive files on a vulnerable system.
Reports indicated that proof-of-concept (PoC) exploit codes for elevation of privilege vulnerabilities (CVE-2026-43494 and CVE-2026-46333) are publicly available and they are at high risk of exploitation. System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
Affected Systems:
- Linux kernel versions 3.16.52 through 3.17 (excluding 3.17)
- Linux kernel versions 4.4.40 through 4.5 (excluding 4.5)
- Linux kernel versions 4.8.16 through 4.9 (excluding 4.9)
- Linux kernel versions 4.9.1 through 4.10
- Linux kernel versions 4.17
Impact:
Successful exploitation of the vulnerabilities could lead to elevation of privilege or information disclosure on an affected system.
Recommendation:
The vulnerabilities are fixed in some of the affected Linux distributions including Debian, Red Hat, SUSE and Ubuntu. The following is only a sample list of Linux distributions that are affected. The list is not exhaustive and it is strongly recommended to consult the product vendors if the used Linux systems are affected. System administrators should check with their product vendors to confirm if their Linux systems are affected and the availability of patches, and if so, apply the patches or follow the recommendations provided by the product vendors to mitigate the risk.
Debian
https://security-tracker.debian.org/tracker/CVE-2026-43494
Debian
https://security-tracker.debian.org/tracker/CVE-2026-46333
Red Hat
https://access.redhat.com/security/cve/cve-2026-43494
Red Hat
https://access.redhat.com/security/cve/cve-2026-46333
SUSE
https://www.suse.com/security/cve/CVE-2026-43494.html
SUSE
https://www.suse.com/security/cve/CVE-2026-46333.html
Ubuntu
https://ubuntu.com/security/CVE-2026-43494
Ubuntu
https://ubuntu.com/security/CVE-2026-46333
More Information:
- https://security-tracker.debian.org/tracker/CVE-2026-43494
- https://security-tracker.debian.org/tracker/CVE-2026-46333
- https://access.redhat.com/security/cve/cve-2026-43494
- https://access.redhat.com/security/cve/cve-2026-46333
- https://www.suse.com/security/cve/CVE-2026-43494.html
- https://www.suse.com/security/cve/CVE-2026-46333.html
- https://ubuntu.com/security/CVE-2026-43494
- https://ubuntu.com/security/CVE-2026-46333
- https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn
- https://github.com/v12-security/pocs/tree/09e835b587bf71249775654061ae4c79e92cf430/pintheft
- https://nvd.nist.gov/vuln/detail/CVE-2026-43494
- https://nvd.nist.gov/vuln/detail/CVE-2026-46333
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43494
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-46333