Description
In the Linux kernel, the following vulnerability has been resolved:

smack: fix cred UAF in smack_file_send_sigiotask()

When inspecting the credentials of another task, objective credentials
(->real_cred, accessed with __task_cred()) must always be used.

Accessing ->cred on a non-current task is forbidden unless that task is
being created or destroyed; a task is allowed to change its own ->cred
pointer with no synchronization, and changing ->cred should only affect the
current syscall.

smack_file_send_sigiotask() was accessing both sets of credentials: First
tsk->cred, then __task_cred(tsk).

Fix it, always access the objective credentials here.

I have tested that this bug can lead to a KASAN-reported UAF of struct cred
in smack_file_send_sigiotask(), and that this fix prevents the race.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via kernel credential use‑after‑free
Action: Patch Immediately
AI Analysis

Impact

The smack module in the Linux kernel contains a use‑after‑free bug in smack_file_send_sigiotask(). The function wrongly accesses both tsk->cred and __task_cred(tsk) while a task’s credentials are being re‑assigned, leading to a freed credential structure being dereferenced. If an attacker can trigger the kernel to execute this code path on a local machine, the race can result in kernel memory corruption or the leakage of administrator credentials, effectively granting elevated privileges. The flaw is a classic use‑after‑free scenario (CWE‑825) that can be exploited from local user space.

Affected Systems

All Linux kernel releases that do not incorporate the commit that fixes smack_file_send_sigiotask() are vulnerable. The exact kernel version impacted cannot be enumerated without the advisory’s release notes, but any system running a kernel older than the first occurrence of the fix is at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates moderate‑to‑high seriousness, while the EPSS score of < 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local process that forces the kernel to execute smack_file_send_sigiotask(), such as via interprocess signalling; this inference is drawn from the description of how the fix removed the race. Successful exploitation would require precise timing to create the race and is therefore technically challenging, but once achieved it can lead to arbitrary kernel execution and privilege escalation.

Generated by OpenCVE AI on September 21, 2026 at 04:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the patch commit for smack_file_send_sigiotask()
  • Enable kernel hardening mechanisms such as KASAN or stack protection to detect or mitigate the use‑after‑free (CWE‑825) at runtime
  • Continuously monitor kernel logs and audit systems for memory corruptions or KASAN messages indicating potential exploitation of the use‑after‑free (CWE‑825) bug

Generated by OpenCVE AI on September 21, 2026 at 04:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a non-current task is forbidden unless that task is being created or destroyed; a task is allowed to change its own ->cred pointer with no synchronization, and changing ->cred should only affect the current syscall. smack_file_send_sigiotask() was accessing both sets of credentials: First tsk->cred, then __task_cred(tsk). Fix it, always access the objective credentials here. I have tested that this bug can lead to a KASAN-reported UAF of struct cred in smack_file_send_sigiotask(), and that this fix prevents the race.
Title smack: fix cred UAF in smack_file_send_sigiotask()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:58:55.805Z

Reserved: 2026-08-26T14:34:25.802Z

Link: CVE-2026-80928

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:56.513

Modified: 2026-09-14T13:18:49.050

Link: CVE-2026-80928

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:04Z

Links: CVE-2026-80928 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:00:14Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference