New Linux pedit COW exploit enables root access by poisoning cached binaries; affects RHEL and Debian with unprivileged user namespaces open by default.
DebianUbuntuRed Hat, Inc.Red Hat

New Linux pedit COW exploit enables root access by poisoning cached binaries; affects RHEL and Debian with unprivileged user namespaces open by default.

A new Linux kernel vulnerability allows unprivileged users to gain root access by exploiting a Copy-on-Write (COW) flaw affecting RHEL and Debian systems, which have unprivileged user namespaces enabled by default. The exploit targets cached binaries, specifically the setuid-root binary /bin/su.

CyberSecurityNews CyberSecurityNews+1 source46 min ago
CuriousCats Full Story

A newly disclosed Linux kernel vulnerability is allowing unprivileged local users to escalate their privileges to root on major Linux distributions, including RHEL and Debian. This exploit takes advantage of a Copy-on-Write (COW) page-cache corruption flaw found in kernel versions v5.18 through v7.1-rc6, which was patched in v7.1-rc7.3

The exploit works by poisoning the cached copy of the setuid-root binary /bin/su in memory, injecting a payload that executes setgid(0) and setuid(0), ultimately providing the attacker with a root shell. This method does not alter the file on disk, making it particularly stealthy.2

Both RHEL and Debian are vulnerable by default, as they ship with unprivileged user namespaces enabled. In contrast, Ubuntu has implemented restrictions through its AppArmor profiles, blocking unprivileged user namespace creation, although the underlying kernel remains susceptible. Debian versions 11 and 12 are still listed as vulnerable, while Red Hat has confirmed that RHEL 8, 9, and 10 are affected, but RHEL 7 is not.678

The CVE was assigned when the fix was merged on June 16, and a weaponized proof-of-concept was reported shortly thereafter, highlighting the urgency for users to apply patches to mitigate this risk.

Key Insight
“A newly disclosed Linux kernel vulnerability allows unprivileged local attackers to escalate privileges to root access. This exploit affects several major Linux distributions, including RHEL and Debian, which ship with unprivileged user namespaces enabled by default.”
CuriousCats studied:
1
CyberSecurityNewsCyberSecurityNews
“A newly disclosed Linux kernel vulnerability combining a Copy-on-Write (COW) page-cache corruption flaw with the `net/sched` subsystem’s `act_pedit` component is enabling unprivileged local attackers to escalate privileges to full root access on several major Linux distributions.”
CyberSecurityNews →
2
The Hacker NewsThe Hacker News
“A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems.”
The Hacker News →
Ask CuriousCats
Who discovered the Linux pedit COW exploit?
What are user namespaces in Linux?
Why is root access significant for attackers?
Are other Linux distributions affected by this vulnerability?
How does this exploit compare to previous Linux vulnerabilities?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats