A newly disclosed Linux kernel vulnerability tracked as CVE-2026-46242 and nicknamed "Bad Epoll" allows any unprivileged user to gain full root access on Linux desktops, servers, and Android devices. A working proof-of-concept exploit has been published, and security teams are urged to patch immediately.
The Bad Epoll vulnerability sits in the same epoll code where Anthropic's Mythos AI recently found a different bug (CVE-2026-43074). The AI found one flaw but missed this deeper, more dangerous sibling. A human researcher, Jaeyoung Chung, discovered it and built an exploit that succeeds roughly 99% of the time.
Vulnerability Details
Bad Epoll (CVE-2026-46242, CVSS 7.8) is a race-condition use-after-free bug in the Linux kernel's epoll subsystem. Epoll is the standard I/O event notification facility that lets programs efficiently monitor many file descriptors at once. Every Linux server, desktop, and network service depends on it.
The bug works like this: when one epoll instance monitors another and both are closed simultaneously, the kernel frees an internal object while another part of the kernel is still writing to it. This collision corrupts kernel memory and lets an attacker escalate from a normal user account to root.
The race window is exceptionally narrow only about six machine instructions wide. Chung's exploit widens this window and retries automatically without crashing the system, achieving root on approximately 99% of tested systems. The exploit uses a Return-Oriented Programming (ROP) chain to hijack control flow after leaking kernel memory.
Impact Assessment
What makes Bad Epoll particularly dangerous:
Chrome sandbox escape. The exploit can be triggered from inside Chrome's renderer sandbox, which blocks most other kernel privilege escalation bugs. This means an attacker who compromises a browser tab can break out of the sandbox and take over the entire system.
Android devices affected. Unlike many Linux kernel flaws that impact only servers, Bad Epoll also affects Android devices running kernel 6.4 or newer. Pixel 10 devices running kernel 6.6 have been confirmed vulnerable. An Android-specific exploit is still in development.
No known in-the-wild exploitation. As of this writing, Bad Epoll has not been added to CISA's Known Exploited Vulnerabilities catalog, and there are no reports of real-world attacks. However, with a public PoC now available, that situation could change quickly.
Affected Systems
All Linux distributions based on kernel version 6.4 or newer are vulnerable unless they have applied the fix. This includes:
- Mainline Linux distributions released since mid-2023
- Android devices running kernel 6.4+ (Pixel 10 confirmed)
- Container hosts and cloud workloads on recent kernels
Kernels based on version 6.1 or older (including the Pixel 8) are not affected, as the bug was introduced in kernel 6.4 via a single commit in 2023.
Mitigation and Patching
Epoll cannot be disabled it is a core kernel mechanism that virtually every Linux program relies on. There is no workaround other than patching.
Apply the upstream fix commit a6dc643c6931 from the Linux kernel tree. Alternatively, install your distribution's backported security update when it becomes available.
Distribution-specific steps:
- Ubuntu/Debian: Run
sudo apt update && sudo apt upgradeand reboot - RHEL/Fedora/CentOS: Run
sudo dnf upgradeand reboot - Arch Linux: Run
sudo pacman -Syuand reboot - Android: Wait for your device manufacturer's monthly security update
Note that the maintainers' first patch did not fully fix the issue. A correct patch landed only two months after the bug was first reported, which is unusually long for a kernel security fix.
Detection
There are no simple indicators of compromise specific to Bad Epoll exploitation. The exploit does not leave obvious log entries and does not trigger KASAN (the kernel's memory error detector) after the sibling CVE-2026-43074 is patched.
The best detection is proactive: verify your kernel version and patch status. Run uname -r to check your running kernel version. If it is 6.4 or newer, confirm the fix commit a6dc643c6931 is included.
The AI Angle
Bad Epoll has a fascinating backstory. In early 2026, Anthropic's Mythos AI (its most powerful model) found a related race condition in the epoll code, now tracked as CVE-2026-43074. That was a genuine achievement because race-condition bugs are notoriously difficult to find, even for expert humans.
However, Mythos missed Bad Epoll. The reason is instructive: once CVE-2026-43074 was patched, Bad Epoll's memory corruption no longer triggers KASAN, the kernel's primary bug detector. With no alert flagging the issue, the sibling flaw went undetected.
This episode demonstrates that AI-assisted vulnerability research, while powerful, is not yet comprehensive. Race conditions remain hard at every stage: hard for AI to find comprehensively, hard for maintainers to fix correctly on the first attempt, and hard for attackers to exploit reliably. As Chung notes, "the bug an AI walks past is still the one a person has to catch."
Frequently Asked Questions
Can Bad Epoll be triggered remotely? No. It requires local access to the system with the ability to execute code. However, combined with a remote code execution vulnerability or a browser compromise, it becomes a full remote take over.
Will a reboot fix the vulnerability permanently? No. Rebooting only clears the current kernel state. You must apply the kernel patch and reboot for the fix to take effect.
Is my cloud server affected? If your cloud instance runs kernel 6.4 or newer, yes. Check with your provider about their patching schedule. Major cloud providers typically deploy kernel updates quickly.
Does this affect containers? Container isolation relies on the host kernel, so a container breakout via Bad Epoll is theoretically possible. The FUSE-based CVE-2026-31694 (found by Bynario) is a more direct container risk, but Bad Epoll should not be ignored in container environments.
Is there a way to mitigate without rebooting? No. Kernel live patching (KSplice, Kpatch, Livepatch) may work if the distributor provides a live patch. Check with your kernel vendor.
Key Takeaways
- CVE-2026-46242 (Bad Epoll) is a use-after-free in the Linux kernel's epoll subsystem allowing local privilege escalation to root
- Affects all systems running kernel 6.4 or newer, including Android
- Working exploit achieves root 99% of the time and can escape Chrome's sandbox
- Apply upstream commit
a6dc643c6931or your distribution's security update - No in-the-wild exploitation reported yet but a public PoC is available
- The bug highlights both the power and limitations of AI-assisted vulnerability research
The Bad Epoll vulnerability serves as an important reminder that kernel security requires constant vigilance. Patch early, verify your kernel version, and stay informed about emerging threats.
Sources: The Hacker News, SecurityWeek, BleepingComputer
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.