PT-2026-64592 · Linux+1 · Linux Kernel+1

CVE-2026-64371

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the procfs component where the ptrace may access() function is called without the necessary exec update lock protection. This lack of locking occurs within the following functions:
  • do task stat()
  • proc pid wchan()
  • proc ns get link()
  • proc ns readlink() Additionally, the functions proc map files lookup() and proc map files readdir() incorrectly use get task mm() instead of mm access().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-93840
CVE-2026-64371
OESA-2026-3453
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu