Description
In the Linux kernel, the following vulnerability has been resolved:

landlock: Fix LOG_SUBDOMAINS_OFF inheritance across fork()

hook_cred_transfer() only copies the Landlock security blob when the
source credential has a domain. This is inconsistent with
landlock_restrict_self() which can set LOG_SUBDOMAINS_OFF on a
credential without creating a domain (via the ruleset_fd=-1 path): the
field is committed but not preserved across fork() because the child's
prepare_creds() calls hook_cred_transfer() which skips the copy when
domain is NULL.

This breaks the documented use case where a process mutes subdomain logs
before forking sandboxed children: the children lose the muting and
their domains produce unexpected audit records.

Fix this by unconditionally copying the Landlock credential blob.
Published: 2026-05-27
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Landlock security module in the Linux kernel fails to propagate the LOG_SUBDOMAINS_OFF flag when a process forks, causing child subprocesses to emit audit subdomain logs that the parent process intended to mute. This unintended audit output leads to disclosure of sensitive operations, representing an information‑disclosure weakness.

Affected Systems

All Linux kernels containing the Landlock module before the included patch are affected. No specific version range is enumerated, so any kernel lacking the fix is at risk.

Risk and Exploitability

The flaw is local; an attacker who can fork a process may trigger undesired audit entries that reveal confidential data. EPSS is unavailable, the vulnerability is not listed in CISA KEV, and no CVSS score is reported. Given its local scope and potential privacy impact, the risk is moderate.

Generated by OpenCVE AI on May 28, 2026 at 04:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the Landlock LOG_SUBDOMAINS_OFF inheritance fix.
  • If an immediate kernel update is not possible, modify audit rules to filter or redact subdomain logs generated by Landlock processes.
  • Continuously monitor audit logs for unexpected subdomain entries to detect any leakage until the kernel patch is deployed.

Generated by OpenCVE AI on May 28, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Thu, 28 May 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 28 May 2026 00:15:00 +0000


Wed, 27 May 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: landlock: Fix LOG_SUBDOMAINS_OFF inheritance across fork() hook_cred_transfer() only copies the Landlock security blob when the source credential has a domain. This is inconsistent with landlock_restrict_self() which can set LOG_SUBDOMAINS_OFF on a credential without creating a domain (via the ruleset_fd=-1 path): the field is committed but not preserved across fork() because the child's prepare_creds() calls hook_cred_transfer() which skips the copy when domain is NULL. This breaks the documented use case where a process mutes subdomain logs before forking sandboxed children: the children lose the muting and their domains produce unexpected audit records. Fix this by unconditionally copying the Landlock credential blob.
Title landlock: Fix LOG_SUBDOMAINS_OFF inheritance across fork()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-06-14T17:51:11.492Z

Reserved: 2026-05-13T15:03:33.094Z

Link: CVE-2026-46057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-05-27T14:17:25.433

Modified: 2026-06-16T14:54:00.107

Link: CVE-2026-46057

cve-icon Redhat

Severity :

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-46057 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T04:30:06Z

Weaknesses