PatchSiren cyber security CVE debrief
CVE-2026-46333 Git CVE debrief
CVE-2026-46333 is a Linux kernel access-control issue in ptrace-related dumpability checks. The fix changes how the kernel decides access for tasks that no longer have an mm, so the ptrace path behaves more consistently for threads without a memory image, including kernel threads.
- Vendor
- Git
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-15
- Original CVE updated
- 2026-08-24
- Advisory published
- 2026-05-15
- Advisory updated
- 2026-08-24
Who should care
Linux kernel maintainers, distro security teams, and operators of multi-user systems or environments that rely on ptrace restrictions should review this advisory. Systems that permit local users, debug tooling, or kernel-thread introspection deserve the most attention.
Technical summary
The reported problem is that "dumpability" is fundamentally tied to a task's memory image, but ptrace_may_access() also used it for checks unrelated to an mm pointer. That created an odd special case for threads without an mm, including kernel threads. The resolved logic uses a cached "last dumpability" value when a task no longer has an mm but previously had one, and requires CAP_SYS_PTRACE to override. The description also notes that uid/gid matching still applies, so this is an access-check refinement rather than a change to the basic identity check.
Defensive priority
High on systems that expose local users, debugging workflows, or sensitive multi-threaded services; otherwise medium. Because this affects kernel access control and ptrace behavior, patching should be prioritized in general-purpose Linux deployments.
Recommended defensive actions
- Apply the vendor or distribution kernel update that includes the ptrace get_dumpable() fix.
- Review any tooling, monitoring, or hardening controls that depend on ptrace access behavior for tasks without an mm.
- Verify whether local users or service accounts can reach debugging or inspection paths that depend on ptrace permissions.
- Track downstream distribution advisories and stable-kernel backports referenced by the NVD record.
- Treat CAP_SYS_PTRACE as the explicit override path and confirm least-privilege policies are still appropriate after patching.
Evidence notes
The CVE was published in the supplied source data on 2026-05-15T14:16:35.793Z and modified on 2026-05-16T13:16:16.810Z. The description states the issue is resolved by adjusting ptrace get_dumpable() logic for tasks without an mm and by requiring CAP_SYS_PTRACE to override. The NVD metadata also references multiple kernel.org stable commits and advisory posts, but no CVSS score or weakness IDs were provided in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46333 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46333
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46333 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46333
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/01363cb3fbd0238ffdeb09f53e9039c9edf8a730
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/15b828a46f305ae9f05a7c16914b3ce273474205
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2a93a4fac7b6051d3be7cd1b015fe7320cd0404d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4709234fd1b95136ceb789f639b1e7ea5de1b181
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6e5b51e74a40d377bcd3081dd33fbaa0e1aa7e3d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8f907d345bae8f4b3f004c5abc56bf2dfb851ea7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/93d4ba49d18e3d7fb41a9927c2d0cca5e9dfefd6
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.