CVE-2026-64375

Summary

In the Linux kernel, the following vulnerability has been resolved:

proc: protect ptrace_may_access() with exec_update_lock (FD links)

proc_pid_get_link() and proc_pid_readlink() currently look up the task from the pid once, then do the ptrace access check on that task, then look up the task from the pid a second time to do the actual access. That's racy in several ways.

To fix it, pass the task to the ->proc_get_link() handler, and instead of proc_fd_access_allowed(), introduce a new helper call_proc_get_link() that looks up and locks the task, does the access check, and calls ->proc_get_link().

Affected Software

VendorProductVersion RangeStatus
LinuxLinux778c1144771f0064b6f51bee865cceb0d996f2f9 < 6253dfee5afba536bb54fc6fe6c091c3758fafe1affected
LinuxLinux778c1144771f0064b6f51bee865cceb0d996f2f9 < 65bf0d2b6e914f1448d6a2fde193dcf60936a651affected
LinuxLinux778c1144771f0064b6f51bee865cceb0d996f2f9 < de497d7aa2fae453a7e7c8f7d3e8682e565e3aafaffected
LinuxLinux778c1144771f0064b6f51bee865cceb0d996f2f9 < 138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2affected
LinuxLinux778c1144771f0064b6f51bee865cceb0d996f2f9 < 83b17872e3166c295c599279fc9562ac3840c638affected
LinuxLinux778c1144771f0064b6f51bee865cceb0d996f2f9 < 497c6bae5167428596575f20af6613ff5671f383affected
LinuxLinux778c1144771f0064b6f51bee865cceb0d996f2f9 < dfd1894cb64cbd8758b461ed713800fe73db4f82affected
LinuxLinux778c1144771f0064b6f51bee865cceb0d996f2f9 < 6255da28d4bb5349fe18e84cb043ccd394eba75daffected
LinuxLinux2.6.18affected
LinuxLinux0 < 2.6.18unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.4 <= 7.1.*unaffected
LinuxLinux7.2-rc1 <= *unaffected

Weaknesses

References