2026-05-23NOTABLECVE-2026-46333 ssh-keysign-pwn: a 9-year ptrace race in the Linux kernel reaching root and SSH host keys
ssh-keysign-pwn; 9-year ptrace race in Linux kernel __ptrace_may_access() reaches root + SSH host-key exfiltration; four public Qualys exploits on default major distros
cve · CVE-2026-46333
Coverage
1
first 2026-05-23 → last 2026-05-24
Latest activity
2026-05-23
CVE-2026-46333 ssh-keysign-pwn: a 9-year ptrace race in the Linux kernel reaching root and SSH host keys
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, technology, education
Sources cited
8
5 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-46333, newest first. Check the date before acting on an older one.
- Roll kernel patches for CVE-2026-46333 on every Linux estate; raise2026-05-23CVE-2026-46333
kernel.yama.ptrace_scope=2as interim on hosts that cannot be rebooted yet. Four working Qualys exploits detailed in the public advisory (exploit code withheld during coordinated disclosure), all major distros affected, SSH host-key exfiltration in the outcome set. Multi-tenant Kubernetes nodes carry highest residual risk. Full detection / hardening package in § 5 Deep Dive below.
Defender insights
What each entry about CVE-2026-46333 tells a defender to do, newest first.
Detection
Story timeline
Hunting pivots
ATT&CK techniques (5 across 3 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- PersistenceCreate or Modify System Process · Create or Modify System Process: Systemd Service
- Privilege EscalationExploitation for Privilege Escalation · Create or Modify System Process · Create or Modify System Process: Systemd Service
- Credential AccessUnsecured Credentials · Unsecured Credentials: Private Keys
Persistence TA0003
T1543Create or Modify System Process×1
Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.
Evidence: 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗
T1543Create or Modify System Process×1
Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.
Evidence: 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗
T1552.004Unsecured Credentials: Private Keys×1
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.
Evidence: 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗
Entries about ssh-keysign-pwn; 9-year ptrace race in Linux kernel __ptrace_may_access() reaches root + SSH host-key exfiltration; four public Qualys exploits on default major distros (1)
Where this entity is cited
Source distribution
- attack.mitre.org3 (38%)
- blog.qualys.com2 (25%)
- bugs.chromium.org1 (12%)
- thehackernews.com1 (12%)
- ubuntu.com1 (12%)
External references
All cited sources (8)
- blog.qualys.comprimaryLooney Tunables (CVE-2023-4911)https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibc-s-ld-so
- blog.qualys.comprimaryQualys TRU primary advisoryhttps://blog.qualys.com/vulnerabilities-threat-research/2026/05/20/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path
- attack.mitre.orgT1068 Exploitation for Privilege Escalationhttps://attack.mitre.org/techniques/T1068/
- attack.mitre.orgT1543.002 Create or Modify System Process: Systemd Servicehttps://attack.mitre.org/techniques/T1543/002/
- attack.mitre.orgT1552.004 Unsecured Credentials: Private Keyshttps://attack.mitre.org/techniques/T1552/004/
- bugs.chromium.orgJann Horn, 2019https://bugs.chromium.org/p/project-zero/issues/detail?id=1856
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/05/9-year-old-linux-kernel-flaw-enables.html
- ubuntu.comCanonical / Ubuntu advisory bloghttps://ubuntu.com/blog/ssh-keysign-pwn-linux-vulnerability-fixes-available