PinTheft
We are aware of the recent CVE-2026-46333 which has a public exploit (‘PinTheft’) and impacts major Linux kernel versions, RHEL included.
It is important to note that this exploit requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. The impacted kernel modules are also not loaded by default within the VQCM VM, preventing exploitation without a privileged user first having loaded these modules.
To ensure peace of mind for our customers and meet the our high levels of security and transparency we have made available a mitigation playbook which can be applied to a running VQCM instance. This will make sure the required changes are made the to the kernel ptrace scope.
If you have any questions about this CVE, please email security@vqcomms.com
To request access to the playbook, please email support@vqcomms.com


