Description
In the Linux kernel, the following vulnerability has been resolved:

arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry

Commit e057b9477232 ("arm64: syscall: Ensure saved x0 is kept in-sync
with tracer updates") attempted to resolve a long-standing issue with
syscall entry tracing, where a tracer is able to manipulate the first
syscall argument without being subjected to seccomp or audit checking.

Unfortunately, that fix was incomplete [1], as it failed to update
'orig_x0' between a tracer updating x0 during a seccomp ptrace exit
(SECCOMP_RET_TRACE) and the seccomp filter being re-evaluated.

Rather than add hooks to the core seccomp code, instead move the
synchronisation code into the ptrace GPR and syscall setting code so
that 'orig_x0' is kept up to date with x0 whenever we're stopped on the
syscall entry path.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Bypass of seccomp filtering and potential privilege escalation
Action: Patch Now
AI Analysis

Impact

A flaw in the arm64 Linux kernel causes the value of the original first syscall argument (orig_x0) to become unsynchronized with the actual argument (x0) when a traced process is stopped on a syscall entry after a SECCOMP_RET_TRACE event. This allows a ptrace tracer that has the necessary privileges to silently alter the first argument of a syscall that is subjected to a seccomp filter, thereby bypassing security policies that are intended to restrict that argument. The effect is a trusted process being able to subvert user‑level security controls without triggering audit or seccomp checks, which can lead to privilege escalation or other severe compromises.

Affected Systems

All arm64 Linux kernels falling within the Linux:Linux vendor scope that have not yet incorporated the fix identified by commit e057b9477232. The patch was merged after the initial intention in commit 88b839ce497c but was incomplete until the later change, so any kernel prior to that commit remains affected. Specific version ranges are not listed, but all builds lacking the described update should be regarded as vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, while the EPSS score of <1% means exploitation is considered unlikely at present; however, the vulnerability is not in the CISA KEV catalog, suggesting no confirmed widespread use yet. An attacker would need to run as a ptrace tracer (e.g., as root or with CAP_SYS_PTRACE) and target a process protected by seccomp. If successful, the attacker can modify syscall arguments bypassing filter checks, potentially leading to system compromise. Applying the kernel fix removes the state inconsistency and restores integrity of seccomp enforcement.

Generated by OpenCVE AI on September 20, 2026 at 00:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version containing commit e057b9477232 or newer to eliminate the unsynchronization flaw
  • Enforce strict ptrace controls by granting CAP_SYS_PTRACE only to trusted processes or using Linux capabilities to limit tracer privileges
  • Audit ptrace usage in the environment, monitor for anomalous syscall argument changes, and update seccomp filters to log or reject mismatched arguments as an additional safeguard

Generated by OpenCVE AI on September 20, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Sat, 19 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry Commit e057b9477232 ("arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates") attempted to resolve a long-standing issue with syscall entry tracing, where a tracer is able to manipulate the first syscall argument without being subjected to seccomp or audit checking. Unfortunately, that fix was incomplete [1], as it failed to update 'orig_x0' between a tracer updating x0 during a seccomp ptrace exit (SECCOMP_RET_TRACE) and the seccomp filter being re-evaluated. Rather than add hooks to the core seccomp code, instead move the synchronisation code into the ptrace GPR and syscall setting code so that 'orig_x0' is kept up to date with x0 whenever we're stopped on the syscall entry path.
Title arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:46.679Z

Reserved: 2026-09-11T19:38:34.805Z

Link: CVE-2026-90347

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:33.453

Modified: 2026-09-18T18:17:54.883

Link: CVE-2026-90347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses
  • CWE-20

    Improper Input Validation