A high-severity local privilege escalation vulnerability (CVE-2026-46331, codenamed ActPedit/pedit COW) has been disclosed in the Linux kernel's packet editing (pedit) subsystem. The flaw in the tcf_pedit_act() function allows attackers with local access to configure traffic control rules to corrupt the page cache of read-only files and gain full root access. Public PoC exploit code is available, raising the urgency. Deepin 25 users are advised to immediately update via the Control Center or by running sudo apt update && sudo apt dist-upgrade, then reboot. The fix is included in the deepin 25.1.1 release.

2m read timeFrom deepin.org
Post cover image
Table of contents
Vulnerability DetailsPatch Deployment Status
440 Impressions