CVE-2026-89766
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
03/10/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
pidfd: hold exec_update_lock around namespace ioctl<br />
<br />
The PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() perform a filesystem<br />
credentials ptrace access check before handing out a namespace file<br />
descriptor. The accompanying comment states that the code "mirrors nsfs<br />
behavior", but, unlike the corresponding procfs paths, it does so without<br />
holding the target task&#39;s exec_update_lock.<br />
<br />
proc_ns_get_link() and proc_ns_readlink() both take exec_update_lock for<br />
reading around the ptrace check and the namespace lookup, so that the<br />
credentials used for the access decision match those of the task when its<br />
namespace is read. Without it, a caller can pass the check against the<br />
target&#39;s old credentials and then read the namespace after the target has<br />
execve()&#39;d a setuid binary and committed new credentials -- accessing<br />
namespace information it should have been denied.<br />
<br />
Hold exec_update_lock for reading around the ptrace check and the<br />
namespace lookup so that pidfd truly mirrors nsfs behavior, as the comment<br />
already claims. open_namespace() itself runs outside the lock: once a<br />
namespace reference is obtained it carries its own refcount and is opened<br />
with the caller&#39;s own credentials, so a concurrent execve() on the target<br />
can no longer affect the outcome.


