Bad Epoll grants root access in the Linux kernel
Researcher Jaeyoung Chung has published Bad Epoll, CVE-2026-46242, a race-condition use-after-free in the Linux kernel's epoll subsystem. The disclosure states that an unprivileged process can gain root on Linux servers, desktops and Android devices, and that the bug can be reached from inside Chrome's renderer sandbox. The public write-up reports a high-reliability exploit in testing and notes there is no practical kill switch, because epoll is a core kernel feature. The Debian tracker describes the kernel fix for the underlying eventpoll file-reference issue. Security teams should prioritise kernel updates on multi-user servers, VDI, CI and build hosts, container hosts, developer workstations and managed Android fleets.
What this means for your organisation
Privilege escalation rarely starts an incident, but it is often what makes it serious. Without it an attacker is confined to a user account; with it they own the machine. Bad Epoll particularly affects shared environments where many users or workloads share one kernel. There, the assumption that users are isolated from each other is the basis of the security model, and that assumption fails here.
Berigo recommends
- Prioritise kernel updates on multi-user servers, container hosts, VDI and build environments ahead of other systems.
- Review which Linux systems run versions without vendor support and plan their replacement.
- Ensure managed Android devices receive updates, and block devices no longer supported.
- Consider separating development and build environments from production so root on a build node does not grant onward access.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch