Description
In the Linux kernel, the following vulnerability has been resolved:

time/namespace: Validate nanosecond field in proc_timens_set_offset()

The function validates tv_sec to be within [-KTIME_SEC_MAX, KTIME_SEC_MAX]
but never validates that tv_nsec is within the valid range of
[0, NSEC_PER_SEC-1] before using it in timespec64_add().

timespec64_add() expects both timespec64 structures to have normalized
values with tv_nsec in the range [0, 999999999]. If off->val.tv_nsec
contains invalid values (negative or >= NSEC_PER_SEC), it could lead to
incorrect calculations or unexpected behavior.

Add validation to ensure tv_nsec is within the valid range before
performing the addition.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Incorrect Time Handling That May Lead to System Instability
Action: Immediate Patch
AI Analysis

Impact

The flaw lies in the time/namespace subsystem of the Linux kernel. The proc_timens_set_offset() function accepts a timespec64 structure and validates only the seconds component, ignoring that the nanoseconds field must be in the range 0 to 999,999,999. This omission allows negative or excessively large values to be passed to timespec64_add(), which expects normalized inputs. The resulting incorrect arithmetic can produce corrupted timestamps and unpredictable time‑keeping behavior, potentially affecting scheduling, logging, or authentication mechanisms dependent on accurate time.

Affected Systems

Affected systems are Linux kernels on all architectures that implement the time‑namespace proc interface without the added validation. The advisory does not provide a specific version range; any kernel that predates the commit adding the check is considered vulnerable.

Risk and Exploitability

The EPSS score indicates that exploitation is expected to be rare, and the vulnerability is not listed in the CISA KEV catalog. No remote exploitation path is documented; an attacker would typically need local code execution or privileged interaction with the /proc/time namespace entries. Without a crafted exploit the risk remains largely theoretical, but the missing validation justifies timely remediation.

Generated by OpenCVE AI on September 19, 2026 at 08:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that incorporates the fix commit 06aba58e58492d2b8eae059274caed29025ea96e.
  • If a kernel update cannot be applied immediately, enforce stricter permissions on the /proc/[pid]/timens or related time‑namespace interfaces so that only privileged users can modify them, preventing unprivileged writes.
  • Continuously monitor kernel logs and system time‑keeping for anomalous entries such as “invalid timespec” errors and alert security personnel when such events occur.

Generated by OpenCVE AI on September 19, 2026 at 08:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: time/namespace: Validate nanosecond field in proc_timens_set_offset() The function validates tv_sec to be within [-KTIME_SEC_MAX, KTIME_SEC_MAX] but never validates that tv_nsec is within the valid range of [0, NSEC_PER_SEC-1] before using it in timespec64_add(). timespec64_add() expects both timespec64 structures to have normalized values with tv_nsec in the range [0, 999999999]. If off->val.tv_nsec contains invalid values (negative or >= NSEC_PER_SEC), it could lead to incorrect calculations or unexpected behavior. Add validation to ensure tv_nsec is within the valid range before performing the addition.
Title time/namespace: Validate nanosecond field in proc_timens_set_offset()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:44.117Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93146

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:09.757

Modified: 2026-09-17T17:18:09.757

Link: CVE-2026-93146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation