Review reviewHigh

CVE-2026-46333

Linux Linux, NVIDIA for RHEL 10, Red Hat Enterprise Linux 10

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don't have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses 'dumpable' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS)...

CVSS
7.1
EPSS
1.50%
71.7% percentile
CISA KEV
Not listed
Published
2026.05.15
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability1.50%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don't have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses 'dumpable' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS)...

Affected product and versions

Product
Linux Linux, NVIDIA for RHEL 10, Red Hat Enterprise Linux 10
Affected versions
>= bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 < 93d4ba49d18e3d7fb41a9927c2d0cca5e9dfefd6, >= bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 < 15b828a46f305ae9f05a7c16914b3ce273474205, >= bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 < 4709234fd1b95136ceb789f639b1e7ea5de1b181, >= bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 < 8f907d345bae8f4b3f004c5abc56bf2dfb851ea7, >= bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 < 6e5b51e74a40d377bcd3081dd33fbaa0e1aa7e3d, >= bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 < 2a93a4fac7b6051d3be7cd1b015fe7320cd0404d, >= bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 < 01363cb3fbd0238ffdeb09f53e9039c9edf8a730, >= bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 < 31e62c2ebbfdc3fe3dbdf5e02c92a9dc67087a3a, >= d5b3e840dbf6dd2c0f30b5982b6f5ecd49e46b12, >= 03eed7afbc09e061f66b448daf7863174c3dc3f3, >= e45692fa1aea06676449b63ef3c2b6e1e72b7578, >= 694a95fa6dae4991f16cda333d897ea063021fed, >= 3.16.52 < 3.17, >= 4.4.40 < 4.5, >= 4.8.16 < 4.9, >= 4.9.1 < 4.10, >= 4.10, >= V3.1.6, >= 4.9.1 < 5.10.256, >= 5.11 < 5.15.207
Fixed versions
3.17, 4.5, 4.9, 5.10.256, 5.15.207, 6.1.173, 6.6.139, 6.12.89, 6.18.31, 7.0.8

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, NVIDIA for RHEL 10, Red Hat Enterprise Linux 10 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE
CWE-269