Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89766

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
03/10/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> pidfd: hold exec_update_lock around namespace ioctl<br /> <br /> The PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() perform a filesystem<br /> credentials ptrace access check before handing out a namespace file<br /> descriptor. The accompanying comment states that the code "mirrors nsfs<br /> behavior", but, unlike the corresponding procfs paths, it does so without<br /> holding the target task&amp;#39;s exec_update_lock.<br /> <br /> proc_ns_get_link() and proc_ns_readlink() both take exec_update_lock for<br /> reading around the ptrace check and the namespace lookup, so that the<br /> credentials used for the access decision match those of the task when its<br /> namespace is read. Without it, a caller can pass the check against the<br /> target&amp;#39;s old credentials and then read the namespace after the target has<br /> execve()&amp;#39;d a setuid binary and committed new credentials -- accessing<br /> namespace information it should have been denied.<br /> <br /> Hold exec_update_lock for reading around the ptrace check and the<br /> namespace lookup so that pidfd truly mirrors nsfs behavior, as the comment<br /> already claims. open_namespace() itself runs outside the lock: once a<br /> namespace reference is obtained it carries its own refcount and is opened<br /> with the caller&amp;#39;s own credentials, so a concurrent execve() on the target<br /> can no longer affect the outcome.

Impacto