we_are_coded.by CODE · The world, decoded
БГ
Bad Epoll

A hole in the heart of Linux hands root to anyone, and AI had walked right past it

CVE.orgSecurity

CVE-2026-46242. Use-after-free in epoll that escalates an ordinary user to root - on desktops, servers, even Android. The irony: Anthropic's AI model Mythos found the neighboring bug in the same code. This exact one, it missed.

In short
  • Bad Epoll (CVE-2026-46242) - a use-after-free in epoll - escalates an ordinary user to root on Linux desktops, servers, and Android.
  • Found by Jaeyoung Chung; a patch already exists. A rare bug that can root Android.
  • The neighboring bug in the same code (from a 2023 change) was found by Anthropic's AI model Mythos - but it missed this one.
Checked on4 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Researcher Jaeyoung Chung finds a flaw in epoll - a core Linux mechanism a program uses to watch many files and connections at once. Through it, an ordinary user with no privileges at all can escalate to root, meaning full control of the machine. And since epoll is everywhere, the hole catches desktops, servers, and Android.

The facts: Bad Epoll (CVE-2026-46242) is a use-after-free - two parts of the kernel free the same object at the same time, while one of them is still writing to it, and this collision allows memory corruption and escalation to root. epoll can't simply be turned off. A patch already exists. Bad Epoll is one of the rare bugs that can root Android - out of roughly 130 vulnerabilities used in Google's kernelCTF (Google's bug-hunting contest), only about 10 are candidates for that. Both bugs - this one and its neighbor - trace back to a single change in the epoll code from 2023.

I've seen this combination before. 'AI found a vulnerability' looks great as a headline, but the real question is who missed what. The neighboring bug in the same short stretch of code (CVE-2026-43074, already patched) was caught by Mythos, the most powerful model made by Anthropic. The same machine passed within inches of this bug and didn't see it. That's the exact boundary of automated auditing today - it raises the floor, but it doesn't take the skeptical human out of the loop.

Running a Linux server or an Android device? The patch is already out. Put it on today.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CVE.org - CVE-2026-46242, official record (Linux kernel CNA)→Bad Epoll - PoC (Jaeyoung Chung)
Original: https://wearecoded.com/en/articles/bad-epoll-linux-root.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news