---
schema: 1
kind: vulnerability
title: "CVE-2026-46331 — Linux kernel \"pedit COW\": out-of-bounds write in the tc act_pedit module (public weaponised PoC)"
headline: "CVE-2026-46331 — Linux kernel \"pedit COW\": out-of-bounds write in the tc act_pedit module (public weaponised PoC)"
summary: "A separate page-cache-corruption LPE, pedit COW, drew a public weaponised PoC (packet_edit_meme) within a day of CVE assignment on 2026-06-16 (Red Hat Product Security, 2026-06-19)."
discovered_at: "2026-06-27T05:17:42Z"
event_date: 2026-06-26
run_id: 2026-06-27-40e791d4
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - lpe
  - priv-esc
  - poc-public
  - patch-available
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-46331
    cvss: n/a
    epss: null
    type: lpe
    vector: local
    auth: post-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://access.redhat.com/security/vulnerabilities/RHSB-2026-008"
    publisher: Red Hat RHSB-2026-008
    role: primary
  - url: "https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html"
    publisher: The Hacker News
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-27.md
---

A separate page-cache-corruption LPE, **pedit COW**, drew a public weaponised PoC (`packet_edit_meme`) within a day of CVE assignment on 2026-06-16 ([Red Hat Product Security, 2026-06-19](https://access.redhat.com/security/vulnerabilities/RHSB-2026-008)). The bug is a missing bounds check in `tcf_pedit_act()` in `net/sched/act_pedit.c`: the function computes the copy-on-write range once before iterating the key list, so writes from later typed keys (whose runtime header offsets are not accounted for) fall outside the private copy and into read-only file-backed page-cache memory — a partial COW. An unprivileged user with `tc` rule-write access (again, obtainable through user namespaces) overwrites the cached `/bin/su` to spawn a root shell ([The Hacker News, 2026-06-26](https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html)). Red Hat confirms RHEL 8/9/10, RHCOS (OpenShift) and RHOSP affected; the flaw is exposed since kernel v5.18 and fixed upstream in v7.1-rc7. Interim mitigation where `tc pedit` is unused: blacklist the `act_pedit` module, or set `kernel.unprivileged_userns_clone=0`.
