CVE-2026-46242. Use-after-free in epoll that escalates an ordinary user to root - on desktops, servers, even Android. The irony: Anthropic's AI model Mythos found the neighboring bug in the same code. This exact one, it missed.
- Bad Epoll (CVE-2026-46242) - a use-after-free in epoll - escalates an ordinary user to root on Linux desktops, servers, and Android.
- Found by Jaeyoung Chung; a patch already exists. A rare bug that can root Android.
- The neighboring bug in the same code (from a 2023 change) was found by Anthropic's AI model Mythos - but it missed this one.
Researcher Jaeyoung Chung finds a flaw in epoll - a core Linux mechanism a program uses to watch many files and connections at once. Through it, an ordinary user with no privileges at all can escalate to root, meaning full control of the machine. And since epoll is everywhere, the hole catches desktops, servers, and Android.
I've seen this combination before. 'AI found a vulnerability' looks great as a headline, but the real question is who missed what. The neighboring bug in the same short stretch of code (CVE-2026-43074, already patched) was caught by Mythos, the most powerful model made by Anthropic. The same machine passed within inches of this bug and didn't see it. That's the exact boundary of automated auditing today - it raises the floor, but it doesn't take the skeptical human out of the loop.
Running a Linux server or an Android device? The patch is already out. Put it on today.