Impact
The Landlock security module in the Linux kernel fails to propagate the LOG_SUBDOMAINS_OFF flag when a process forks, causing child subprocesses to emit audit subdomain logs that the parent process intended to mute. This unintended audit output leads to disclosure of sensitive operations, representing an information‑disclosure weakness.
Affected Systems
All Linux kernels containing the Landlock module before the included patch are affected. No specific version range is enumerated, so any kernel lacking the fix is at risk.
Risk and Exploitability
The flaw is local; an attacker who can fork a process may trigger undesired audit entries that reveal confidential data. EPSS is unavailable, the vulnerability is not listed in CISA KEV, and no CVSS score is reported. Given its local scope and potential privacy impact, the risk is moderate.
OpenCVE Enrichment