PT-2026-90058 · Linux · Linux
CVE-2026-80928
·
Published
2026-09-11
·
Updated
2026-09-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
smack: fix cred UAF in smack file send sigiotask()
When inspecting the credentials of another task, objective credentials
(->real cred, accessed with task cred()) must always be used.
Accessing ->cred on a non-current task is forbidden unless that task is
being created or destroyed; a task is allowed to change its own ->cred
pointer with no synchronization, and changing ->cred should only affect the
current syscall.
smack file send sigiotask() was accessing both sets of credentials: First
tsk->cred, then task cred(tsk).
Fix it, always access the objective credentials here.
I have tested that this bug can lead to a KASAN-reported UAF of struct cred
in smack file send sigiotask(), and that this fix prevents the race.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux