Impact
The Linux kernel exposed the sysctl entry cad_pid as a global variable in the pid_table array, while its handler is only used in the root namespace. Because the variable is global, a non‑root user that creates a PID or user namespace can modify it from the child namespace through the pid_table_root_permissions check. This allows the attacker to change a system‑wide kernel parameter that is normally restricted, potentially enabling privilege escalation. The flaw is an unchecked alteration of a global configuration value, corresponding to CWE-279.
Affected Systems
Affected systems include Linux kernels that still contain the legacy cad_pid entry in the pid_table array. Specific affected versions are not listed in the CVE data, so all releases prior to the relocation commit are potentially vulnerable. Vendors shipping those older kernels are impacted; kernels that incorporate the fix are no longer affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1 % reflects a low probability of widespread exploitation. The issue is not listed in the CISA KEV catalog. Attack conditions are local and rely on a non‑privileged user’s ability to create unprivileged PID or user namespaces; the attacker already needs a local user account. The kernel patch removes the direct privilege escalation vector once applied.
OpenCVE Enrichment