Description
In the Linux kernel, the following vulnerability has been resolved:

sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]

cad_pid is global, and kill_cad_pid() is only used in the root namespace.

However, due to pid_table_root_permissions(), a non-root user can unshare
pid/user namespaces and modify it from the child namespace. This makes no
sense and is simply wrong.

Move it to kern_reboot_table[] where it logically belongs; this ensures
that only GLOBAL_ROOT_UID can read/modify this sysctl.

Note that this patch doesn't preserve "#ifdef CONFIG_PROC_SYSCTL" around
the "cad_pid"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always
set when kern_reboot_table[] is compiled.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel exposed the sysctl entry cad_pid as a global variable in the pid_table array, while its handler is only used in the root namespace. Because the variable is global, a non‑root user that creates a PID or user namespace can modify it from the child namespace through the pid_table_root_permissions check. This allows the attacker to change a system‑wide kernel parameter that is normally restricted, potentially enabling privilege escalation. The flaw is an unchecked alteration of a global configuration value, corresponding to CWE-279.

Affected Systems

Affected systems include Linux kernels that still contain the legacy cad_pid entry in the pid_table array. Specific affected versions are not listed in the CVE data, so all releases prior to the relocation commit are potentially vulnerable. Vendors shipping those older kernels are impacted; kernels that incorporate the fix are no longer affected.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1 % reflects a low probability of widespread exploitation. The issue is not listed in the CISA KEV catalog. Attack conditions are local and rely on a non‑privileged user’s ability to create unprivileged PID or user namespaces; the attacker already needs a local user account. The kernel patch removes the direct privilege escalation vector once applied.

Generated by OpenCVE AI on September 21, 2026 at 03:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the cad_pid relocation commit.
  • Set /proc/sys/kernel/unprivileged_userns_clone to 0 to prevent unprivileged namespace creation.
  • Configure SELinux or AppArmor to enforce that only privileged users can modify /proc/sys/kernel/cad_pid.

Generated by OpenCVE AI on September 21, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-279
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is only used in the root namespace. However, due to pid_table_root_permissions(), a non-root user can unshare pid/user namespaces and modify it from the child namespace. This makes no sense and is simply wrong. Move it to kern_reboot_table[] where it logically belongs; this ensures that only GLOBAL_ROOT_UID can read/modify this sysctl. Note that this patch doesn't preserve "#ifdef CONFIG_PROC_SYSCTL" around the "cad_pid"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always set when kern_reboot_table[] is compiled.
Title sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:10.105Z

Reserved: 2026-08-26T14:34:25.802Z

Link: CVE-2026-80929

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:56.647

Modified: 2026-09-13T07:17:00.663

Link: CVE-2026-80929

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:04Z

Links: CVE-2026-80929 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses
  • CWE-279

    Incorrect Execution-Assigned Permissions