Files
KaraZajac bd63aabd64 modules: add ptrace_pidfd (CVE-2026-46333, Qualys ptrace/pidfd_getfd cred-steal)
New module for Qualys's 2026-05-20 disclosure: a __ptrace_may_access logic flaw leaves a process dropping privileges briefly reachable past its dumpable boundary; pidfd_getfd(2) steals root-opened fds / authenticated channels from it. Default-distro, no userns, arch-agnostic (fd-steal, no shellcode).

detect(): version-pinned, predates-gate at pidfd_getfd's 5.6 introduction; kernel_range from Debian backports (5.10.251/6.1.172/6.12.88/7.0.7), drift-check clean. exploit(): spawns a setuid victim, pidfd_open()s it, sweeps pidfd_getfd() over its fd table during the cred-drop window, reports any uid-0-owned fd captured from a non-root context. Honest EXPLOIT_FAIL without a euid-0 witness; not yet VM-verified. mitigate(): yama ptrace_scope=2; cleanup() reverts. auditd/sigma/falco rules, NOTICE.md (Qualys TRU credit) + MODULE.md, safety rank 84.

Wiring: registry, Makefile, cve_metadata (+JSON source), verify-vm/targets.yaml (ubuntu2204 + mainline 5.15.5 target, sweep pending). Docs: README + CVES.md + docs/index.html counts 39->40 modules / 34->35 CVEs; added to not-yet-verified lists + corpus pill.
2026-06-02 08:26:24 -04:00

2.5 KiB

NOTICE — ptrace_pidfd (CVE-2026-46333)

Vulnerability

CVE-2026-46333 — a logic flaw in the Linux kernel's __ptrace_may_access() path leaves a privileged process that is dropping its credentials briefly reachable through ptrace-family operations, even though its dumpable flag should already have closed that path. Paired with pidfd_getfd(2), an unprivileged local user can capture open file descriptors and authenticated IPC channels from a dying privileged process and re-use them under their own uid → local root and credential disclosure.

The underlying flaw has resided in mainline since v4.10-rc1 (November 2016); the pidfd_getfd(2) exploitation vector was added in v5.6 (January 2020). Affects default installations of Debian 13, Ubuntu 24.04 / 26.04, Fedora 43 / 44, SUSE, AlmaLinux, and CloudLinux.

Research credit

Discovered and disclosed by Qualys Threat Research Unit (TRU), published 2026-05-20. The four proof-of-concept exploits demonstrated by Qualys targeted chage, ssh-keysign, pkexec, and accounts-daemon.

All research credit for finding and analysing this bug belongs to Qualys. SKELETONKEY is the bundling and bookkeeping layer only.

SKELETONKEY role

🟡 Primitive / ported-from-disclosure — not yet VM-verified. detect() is version-pinned against the Debian backport thresholds above (kernels < 5.6 are reported OK, lacking the bundled vector). exploit() fires the real primitive: it spawns a setuid victim, pidfd_open()s it, and sweeps pidfd_getfd() across its descriptor table during the credential-drop window, recording whether a root-owned descriptor is actually captured from a non-root context. It returns EXPLOIT_FAIL unless it can witness euid 0 — the target-specific fd-weaponization that lands a root shell is not bundled until it can be verified end-to-end against a real vulnerable VM, in keeping with the project's no-fabrication rule.

--mitigate sets kernel.yama.ptrace_scope=2 (the check pidfd_getfd rides); --cleanup restores it. Architecture-agnostic — the technique steals descriptors rather than injecting shellcode.