PT-2026-25886 · Linux+2 · Linux Kernel+2

·

CVE-2026-23241

·

Publicado

2026-01-01

·

Atualizado

2026-08-21

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel has an issue where the 'at' variant of the getxattr() and listxattr() system calls are not included in the audit read class. This allows bypassing audit rules when calling getxattrat() or listxattrat() on a file to read its extended attributes. Specifically, rules defined with the -w option, such as -w /tmp/test -p rwa -k test rwa, may be circumvented. The current patch addresses this by adding the missing system calls to the audit read class.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Protection Mechanism Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-12292
CVE-2026-23241
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8597-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8668-1

Produtos afetados

Linuxmint
Linux Kernel
Ubuntu