Description
In the Linux kernel, the following vulnerability has been resolved:

pidfd: hold exec_update_lock around namespace ioctl

The PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() perform a filesystem
credentials ptrace access check before handing out a namespace file
descriptor. The accompanying comment states that the code "mirrors nsfs
behavior", but, unlike the corresponding procfs paths, it does so without
holding the target task's exec_update_lock.

proc_ns_get_link() and proc_ns_readlink() both take exec_update_lock for
reading around the ptrace check and the namespace lookup, so that the
credentials used for the access decision match those of the task when its
namespace is read. Without it, a caller can pass the check against the
target's old credentials and then read the namespace after the target has
execve()'d a setuid binary and committed new credentials -- accessing
namespace information it should have been denied.

Hold exec_update_lock for reading around the ptrace check and the
namespace lookup so that pidfd truly mirrors nsfs behavior, as the comment
already claims. open_namespace() itself runs outside the lock: once a
namespace reference is obtained it carries its own refcount and is opened
with the caller's own credentials, so a concurrent execve() on the target
can no longer affect the outcome.
Published: 2026-09-11
Score: 2.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Namespace Access
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s pidfd interface allows a process to request a namespace file descriptor through the PIDFD_GET_*_NAMESPACE ioctls. The code performs a ptrace access check before returning the descriptor but does not hold the exec_update_lock during the check or the namespace lookup. Consequently, if the target process has already executed a set‑uid binary and changed credentials immediately before the ioctl, the access check can succeed with stale credentials, allowing the caller to obtain a descriptor to the target’s namespace after credentials have been of namespace information and is a timing‑to‑time‑of‑use flaw (CWE‑367).

Affected Systems

adds holding exec_update_lock around PIDFD_GET_*_NAMESPACE ioctls are affected. Any distribution shipping the unpatched kernel, regardless of configuration, process‑namespace subsystem.

Risk and Exploitability

The vulnerability has a CVSS score of 2.5, indicating low severity, and an EPSS score of less than 1%. It is not listed in the CISA KEV catalog. Exploitation requires a local attacker with access to a target process’s pidfd descriptor and precise timing between the target’s credential change and the IOCTL request. In practice this confines risk to privileged or set‑uid processes that can observe or influence other tasks. The low EPSS value and absence of known public exploits suggest the vulnerability is not widely abused, but the potential for sensitive namespace disclosure warrants patching.

Generated by OpenCVE AI on September 15, 2026 at 19:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that holds exec_update_lock around the PIDFD_GET_*_NAMESPACE ioctls.
  • If immediate upgrade is not possible, enforce SELinux or AppArmor policies that restrict the use of PIDFD_GET_*_NAMESPACE to trusted users or minimal‑privilege processes.
  • Reduce the likelihood of the race condition by minimizing the use of set‑uid binaries and applying strict privilege separation so credential changes are not performed concurrently with pidfd namespace requests.

Generated by OpenCVE AI on September 15, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: pidfd: hold exec_update_lock around namespace ioctl The PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() perform a filesystem credentials ptrace access check before handing out a namespace file descriptor. The accompanying comment states that the code "mirrors nsfs behavior", but, unlike the corresponding procfs paths, it does so without holding the target task's exec_update_lock. proc_ns_get_link() and proc_ns_readlink() both take exec_update_lock for reading around the ptrace check and the namespace lookup, so that the credentials used for the access decision match those of the task when its namespace is read. Without it, a caller can pass the check against the target's old credentials and then read the namespace after the target has execve()'d a setuid binary and committed new credentials -- accessing namespace information it should have been denied. Hold exec_update_lock for reading around the ptrace check and the namespace lookup so that pidfd truly mirrors nsfs behavior, as the comment already claims. open_namespace() itself runs outside the lock: once a namespace reference is obtained it carries its own refcount and is opened with the caller's own credentials, so a concurrent execve() on the target can no longer affect the outcome.
Title pidfd: hold exec_update_lock around namespace ioctl
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:47:06.597Z

Reserved: 2026-09-11T19:38:34.764Z

Link: CVE-2026-89766

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:07.850

Modified: 2026-09-11T20:20:07.850

Link: CVE-2026-89766

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-11T19:47:06Z

Links: CVE-2026-89766 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition