Description
In the Linux kernel, the following vulnerability has been resolved:

powerpc/syscall: Fix syscall skip handling for seccomp and ptrace

After enabling GENERIC_ENTRY on PowerPC, syscall_enter_from_user_mode()
returns -1 as a sentinel to signal that seccomp or ptrace has intercepted
the syscall and already set a return value via syscall_set_return_value().
system_call_exception() was not handling this sentinel, and since -1UL
is >= NR_syscalls, the code fell into the out-of-range path and returned
-ENOSYS, overwriting the errno already placed in regs->gpr[3].

The naive fix of checking r0 == -1L before the NR_syscalls bounds check
is ambiguous: a user legitimately calling syscall(-1) also produces r0 ==
-1L, and a tracer intercepting such a call would have its injected return
value silently discarded.

Fix this by introducing a thread flag that is set whenever
syscall_set_return_value() explicitly updates the return value. In
system_call_exception(), check and clear this flag before dispatching
the syscall, and return the preset value directly when it is present.
This ensures that an explicitly supplied return value always suppresses
syscall execution, regardless of the syscall number.

This handles all seccomp actions correctly:

- SECCOMP_RET_ERRNO, SECCOMP_RET_TRACE (no tracer), SECCOMP_RET_USER_NOTIF:
all call syscall_set_return_value(), flag is set, injected value returned.
- SECCOMP_RET_TRAP, SECCOMP_RET_KILL: call syscall_rollback() and deliver
a signal; flag is not set, but the process is dying so the return value
is irrelevant.

The fix covers both ppc32 and ppc64 with no #ifdefs.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Incorrect Syscall Return Value leading to Errno Overwrite
Action: Patch
AI Analysis

Impact

The vulnerability arises from the Linux kernel's handling of system calls on PowerPC architectures. When seccomp or ptrace set a custom return value via syscall_set_return_value, the kernel was expected to honor that value. However, due to improper sentinel handling in system_call_exception, the code incorrectly treated the sentinel as a system‑call‑range overflow and returned –ENOSYS, overwriting the intended result placed in the registers. This flaw could mislead applications that rely on accurate syscall return codes, potentially causing denial of service or logic errors in security‑critical code.

Affected Systems

The flaw affects all versions of the Linux kernel running on PowerPC machines prior to the commit that introduces a thread flag for explicit return values. Both 32‑bit and 64‑bit variants are impacted. No other architectures are mentioned, and no specific kernel releases are listed in the data.

Risk and Exploitability

The advisory lists an EPSS score of less than 1 % and notes that the vulnerability is not in CISA's KEV catalog, indicating a low likelihood of targeted exploitation in the wild. Nevertheless, the defect allows a privileged attacker or an attacker with the ability to manipulate seccomp or ptrace (e.g., through a memory corruption vulnerability) to corrupt the error reporting path, leading to abnormal program termination or denial of service. Because the flaw resides in the kernel, it requires a patch to achieve a robust fix.

Generated by OpenCVE AI on September 19, 2026 at 14:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit that introduces the thread flag handling (e.g., by installing the latest stable kernel release).
  • If an immediate kernel upgrade is not feasible, restrict the use of ptrace and seccomp to trusted processes only.
  • Monitor critical applications for abnormal errno values as a temporary mitigation.

Generated by OpenCVE AI on September 19, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: powerpc/syscall: Fix syscall skip handling for seccomp and ptrace After enabling GENERIC_ENTRY on PowerPC, syscall_enter_from_user_mode() returns -1 as a sentinel to signal that seccomp or ptrace has intercepted the syscall and already set a return value via syscall_set_return_value(). system_call_exception() was not handling this sentinel, and since -1UL is >= NR_syscalls, the code fell into the out-of-range path and returned -ENOSYS, overwriting the errno already placed in regs->gpr[3]. The naive fix of checking r0 == -1L before the NR_syscalls bounds check is ambiguous: a user legitimately calling syscall(-1) also produces r0 == -1L, and a tracer intercepting such a call would have its injected return value silently discarded. Fix this by introducing a thread flag that is set whenever syscall_set_return_value() explicitly updates the return value. In system_call_exception(), check and clear this flag before dispatching the syscall, and return the preset value directly when it is present. This ensures that an explicitly supplied return value always suppresses syscall execution, regardless of the syscall number. This handles all seccomp actions correctly: - SECCOMP_RET_ERRNO, SECCOMP_RET_TRACE (no tracer), SECCOMP_RET_USER_NOTIF: all call syscall_set_return_value(), flag is set, injected value returned. - SECCOMP_RET_TRAP, SECCOMP_RET_KILL: call syscall_rollback() and deliver a signal; flag is not set, but the process is dying so the return value is irrelevant. The fix covers both ppc32 and ppc64 with no #ifdefs.
Title powerpc/syscall: Fix syscall skip handling for seccomp and ptrace
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:50.990Z

Reserved: 2026-09-11T19:38:34.804Z

Link: CVE-2026-90339

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:32.520

Modified: 2026-09-17T17:17:32.520

Link: CVE-2026-90339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:30:07Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size