Skip to main content

Share story

Security

Proof-of-Concept Exploit Released for Linux 'Bad Epoll' Root Access Vulnerability

Proof-of-Concept Exploit Released for Linux 'Bad Epoll' Root Access Vulnerability Image: Primary
A proof-of-concept exploit has been released for a Linux kernel vulnerability that allows unprivileged users to gain root access on desktops, servers and Android phones, SecurityWeek reported. The flaw, tracked as CVE-2026-46242 and dubbed Bad Epoll, is a race condition combined with a use-after-free in the kernel's epoll event notification subsystem. Researcher Jaeyoung Chung published technical details and working exploit code after submitting the issue as a zero-day to Google's kernelCTF program. The PoC achieves root privileges by leaking kernel memory, hijacking an indirect call to control the CPU instruction pointer and executing a return-oriented programming chain. The exploit reached about 99 percent reliability on tested systems. Organizations are urged to apply available patches. No confirmed exploitation in the wild has been reported. An Android version of the full exploit remains in development.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from SecurityWeek and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

AI agents develop physical model from quantum-material observations

Researchers report in an arXiv preprint that their AI Theorist system autonomously developed a physical model explaining previously unpublished experimental observations in α-RuCl₃, a candidate material for realizing a Kitaev quan...

Security Capital
Security Capital

Reco raises $55M extension for enterprise AI agent security

Reco raised a $55M Series B extension, bringing its total funding to $140M, TechCrunch reported. The company's technology helps enterprises secure and govern AI agents across software-as-a-service environments, where businesses ar...

Security
Security

ShinyHunters member reportedly detained in Jordan over FBI breach

ShinyHunters member Saif al-Din Khader, known as "Rey," was detained in Jordan and is cooperating to identify other hackers involved in the FBI breach, Reuters reported, citing sources. The hacking group claims to have stolen data...