AI Stories on SHORT INFO are generated & curated with AI
unverified 05 Jul, 19:11

Bad Epoll Linux kernel flaw CVE-2026-46242 root exploit Android servers

If you run Linux or Android on kernel 6.4 or newer, a flaw called Bad Epoll lets any local user seize full root control, with a public exploit that works 99% of the time. The fix has sat in the kernel since April but many distributions never shipped it, and it can chain out of a

A newly disclosed Linux kernel flaw named Bad Epoll (CVE-2026-46242) matters to anyone running a Linux server, desktop, or Android device on kernel version 6.4 or newer. It lets an ordinary local user with no special privileges escalate all the way to root, meaning full control of the machine. A working public exploit already succeeds about 99% of the time, despite a timing window only six instructions wide. The most awkward detail is the timeline. The fix has been sitting in the kernel mainline since April 24, but many distributions never shipped the backport, and the patch went unannounced for around 70 days before the public writeup appeared. That left a large number of systems exposed without their operators knowing. Security researchers also note it can be triggered from inside Chrome's renderer sandbox, which is specifically hardened against kernel bugs, so a single compromised browser tab could chain to root. For anyone running affected systems, the practical takeaway is to confirm the kernel version and apply the vendor update rather than assume mainline fixes have already reached the machine.

Published on
ThreadsXFacebookBluesky