PT-2026-25886 · Linux+2 · Linux Kernel+2

·

CVE-2026-23241

·

Published

2026-01-01

·

Updated

2026-08-21

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel has an issue where the 'at' variant of the getxattr() and listxattr() system calls are not included in the audit read class. This allows bypassing audit rules when calling getxattrat() or listxattrat() on a file to read its extended attributes. Specifically, rules defined with the -w option, such as -w /tmp/test -p rwa -k test rwa, may be circumvented. The current patch addresses this by adding the missing system calls to the audit read class.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12292
CVE-2026-23241
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8597-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8668-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu