A local privilege escalation vulnerability (CVE-2026-46331), dubbed 'pedit COW', has been disclosed in the Linux kernel's tc-pedit traffic control module with a CVSS score of 7.8 (HIGH). It affects Ubuntu releases from 18.04 LTS through 25.10, with Ubuntu 26.04 LTS receiving AppArmor mitigations. On non-container hosts, a published exploit allows local users to gain root. In container environments, it may also enable container escape. Until kernel patches are released, the mitigation involves blocking the act_pedit kernel module via modprobe configuration, regenerating initramfs, and unloading the module. Step-by-step instructions are provided for applying and later removing the mitigation.
Table of contents
ImpactMitigation regression riskAffected releasesHow to check if you are impactedManual mitigationDisabling the mitigation406 Impressions