Impact
The Linux kernel’s pidfd interface allows a process to request a namespace file descriptor through the PIDFD_GET_*_NAMESPACE ioctls. The code performs a ptrace access check before returning the descriptor but does not hold the exec_update_lock during the check or the namespace lookup. Consequently, if the target process has already executed a set‑uid binary and changed credentials immediately before the ioctl, the access check can succeed with stale credentials, allowing the caller to obtain a descriptor to the target’s namespace after credentials have been of namespace information and is a timing‑to‑time‑of‑use flaw (CWE‑367).
Affected Systems
adds holding exec_update_lock around PIDFD_GET_*_NAMESPACE ioctls are affected. Any distribution shipping the unpatched kernel, regardless of configuration, process‑namespace subsystem.
Risk and Exploitability
The vulnerability has a CVSS score of 2.5, indicating low severity, and an EPSS score of less than 1%. It is not listed in the CISA KEV catalog. Exploitation requires a local attacker with access to a target process’s pidfd descriptor and precise timing between the target’s credential change and the IOCTL request. In practice this confines risk to privileged or set‑uid processes that can observe or influence other tasks. The low EPSS value and absence of known public exploits suggest the vulnerability is not widely abused, but the potential for sensitive namespace disclosure warrants patching.
OpenCVE Enrichment