CVE-2026-80929
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
cad_pid is global, and kill_cad_pid() is only used in the root namespace.
However, due to pid_table_root_permissions(), a non-root user can unshare pid/user namespaces and modify it from the child namespace. This makes no sense and is simply wrong.
Move it to kern_reboot_table[] where it logically belongs; this ensures that only GLOBAL_ROOT_UID can read/modify this sysctl.
Note that this patch doesn't preserve "#ifdef CONFIG_PROC_SYSCTL" around the "cad_pid"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always set when kern_reboot_table[] is compiled.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | e054bcbe7e7af2baad3752f1a4916a7fffc0457e < e8527de7fea191fda704792a56081f9009aeec37 | affected |
| Linux | Linux | e054bcbe7e7af2baad3752f1a4916a7fffc0457e < a09bc4eaa67e1a72df3b6d0beb3afeef1e1fdfcd | affected |
| Linux | Linux | e054bcbe7e7af2baad3752f1a4916a7fffc0457e < 7170ca01623b399c97f2ae9d3e228badc1f25ea3 | affected |
| Linux | Linux | 6.17 | affected |
| Linux | Linux | 0 < 6.17 | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/e8527de7fea191fda704792a56081f9009aeec37
- https://git.kernel.org/stable/c/a09bc4eaa67e1a72df3b6d0beb3afeef1e1fdfcd
- https://git.kernel.org/stable/c/7170ca01623b399c97f2ae9d3e228badc1f25ea3
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.