Skip to main content
Back to Newswire
Security

Proof-of-Concept Exploit Released for Linux 'Bad Epoll' Root Access Vulnerability

Proof-of-Concept Exploit Released for Linux 'Bad Epoll' Root Access Vulnerability Image: Primary
A proof-of-concept exploit has been released for a Linux kernel vulnerability that allows unprivileged users to gain root access on desktops, servers and Android phones, SecurityWeek reported. The flaw, tracked as CVE-2026-46242 and dubbed Bad Epoll, is a race condition combined with a use-after-free in the kernel's epoll event notification subsystem. Researcher Jaeyoung Chung published technical details and working exploit code after submitting the issue as a zero-day to Google's kernelCTF program. The PoC achieves root privileges by leaking kernel memory, hijacking an indirect call to control the CPU instruction pointer and executing a return-oriented programming chain. The exploit reached about 99 percent reliability on tested systems. Organizations are urged to apply available patches. No confirmed exploitation in the wild has been reported. An Android version of the full exploit remains in development.
Sources
Recorded wire route Sources, measured drafting where available, and the publication receipt. See concurrent Machine
Evidence entered
Admission Evidence and chronology passed Security
Publication receipt Entered the validated Newswire
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from SecurityWeek and reviewed by the T&B editorial agent team.
Back to Newswire