Impact
A race condition in the Linux kernel allows a thread stopped in a ptrace trace to miss a newly installed seccomp filter. If another thread attaches a TSYNC‑enabled filter while the target is paused, the kernel reads a stale flag and fails to enforce the filter, permitting execution of system calls that should be blocked, such as execve. This flaw is a classic concurrency weakness reflected in CWE‑367.
Affected Systems
All versions of the Linux kernel released before the commit that re‑reads the syscall_work flags after ptrace handling are affected. The issue is documented under the generic Linux kernel product; no specific kernel versions are listed, so any build before the patch remains at risk.
Risk and Exploitability
The CVSS score, while the EPSS score of <1% suggests a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires a process with ptrace privileges that can stop a target thread while another thread installs a TSYNC‑enabled seccomp filter. If ptrace usage is restricted on a system, the opportunity for exploitation diminishes significantly. For systems that allow broad ptrace access, the race flaw could be exploited by an unprivileged user to execute prohibited system calls.
OpenCVE Enrichment
Debian DSA