New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries
A critical Linux kernel vulnerability dubbed DirtyClone is circulating, enabling local users to escalate privileges to root access.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A new exploit targeting the Linux kernel, identified as DirtyClone, has been identified. The vulnerability utilizes a pedit COW (Copy-On-Write) mechanism to poison cached binaries, potentially allowing local users to gain root system access.
Coverage from outlets including The Hacker News, Security Affairs, SC Media, and Linuxiac highlights the nature of the flaw, noting that it allows privilege escalation via cloned packets. Reports state that two proof-of-concept (PoC) exploits have been published, with some sources mentioning the potential for the activity to leave no trace on a disk.
Future developments will depend on the release of patches or official guidance for system administrators. Coverage does not yet specify the scope of affected Linux distributions or the timeline for a security resolution.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 43d ago.
Quick answers
What is the DirtyClone vulnerability?
It is a Linux kernel flaw that allows local users to achieve root privilege escalation through the poisoning of cached binaries using cloned packets.
What mechanism does the exploit use?
The exploit involves a pedit COW (Copy-On-Write) method.
Has proof-of-concept code been released?
Yes, coverage from SC Media indicates that two proof-of-concept exploits have been published.
Coverage (9)
- New Critical Linux Vulnerability Enables Root Privilege Escalation LinkedIn · 46d ago
- DirtyClone: A Linux Privilege Escalation That Leaves No Trace on Disk Security Affairs · 46d ago
- New Linux pedit COW Exploit Allows Attackers to Gain System Root Access CyberSecurityNews · 46d ago
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets The Hacker News · 46d ago
- Linux Gets Dirty Again: DirtyClone Kernel Flaw Can Lead to Local Root Access Linuxiac · 46d ago
- 2 Linux kernel flaw PoCs published, enabling local privilege escalation | news SC Media · 46d ago
- New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets CyberSecurityNews · 46d ago
- ssh-keysign-pwn Korben · 46d ago
- New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries The Hacker News · 46d ago
Topics
Related trends
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Microsoft has released its August 2026 Patch Tuesday updates, addressing 400 vulnerabilities including three actively exploited zero-day flaws.
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
A critical zero-click vulnerability in Zoom's screen-sharing feature allowed attackers to take remote control of participant devices.
New Pass-ta-key attack reveals all the things we didn’t know about passkeys
Hackers have identified vulnerabilities in passkeys synced to Google, challenging the premise that they represent a safer future for security.
OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion on advanced cybersecurity tasks
OpenAI has released GPT-5.6-Cyber, a specialized model achieving 95% completion on advanced cybersecurity tasks with reduced refusal rates.
A cybersecurity researcher covered a Toyota in an AI-generated pattern to confuse Flock cameras
A cybersecurity researcher cloaks a Toyota in AI‑generated camouflage to outwit Flock cameras, sparking tech‑media focus.
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
New vulnerabilities in passkey implementations across Windows and Google Chrome may allow attackers to recover private keys or bypass MFA protections.