7.8
CVE-2026-64375
- EPSS 0.13%
- Veröffentlicht 25.07.2026 08:50:26
- Zuletzt bearbeitet 17.08.2026 05:17:40
- CVE-Watchlists
- Unerledigt
proc: protect ptrace_may_access() with exec_update_lock (FD links)
In the Linux kernel, the following vulnerability has been resolved: proc: protect ptrace_may_access() with exec_update_lock (FD links) proc_pid_get_link() and proc_pid_readlink() currently look up the task from the pid once, then do the ptrace access check on that task, then look up the task from the pid a second time to do the actual access. That's racy in several ways. To fix it, pass the task to the ->proc_get_link() handler, and instead of proc_fd_access_allowed(), introduce a new helper call_proc_get_link() that looks up and locks the task, does the access check, and calls ->proc_get_link().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
778c1144771f0064b6f51bee865cceb0d996f2f9
Version <
6253dfee5afba536bb54fc6fe6c091c3758fafe1
Status
affected
Version
778c1144771f0064b6f51bee865cceb0d996f2f9
Version <
65bf0d2b6e914f1448d6a2fde193dcf60936a651
Status
affected
Version
778c1144771f0064b6f51bee865cceb0d996f2f9
Version <
de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf
Status
affected
Version
778c1144771f0064b6f51bee865cceb0d996f2f9
Version <
138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2
Status
affected
Version
778c1144771f0064b6f51bee865cceb0d996f2f9
Version <
83b17872e3166c295c599279fc9562ac3840c638
Status
affected
Version
778c1144771f0064b6f51bee865cceb0d996f2f9
Version <
497c6bae5167428596575f20af6613ff5671f383
Status
affected
Version
778c1144771f0064b6f51bee865cceb0d996f2f9
Version <
dfd1894cb64cbd8758b461ed713800fe73db4f82
Status
affected
Version
778c1144771f0064b6f51bee865cceb0d996f2f9
Version <
6255da28d4bb5349fe18e84cb043ccd394eba75d
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.18
Status
affected
Version
0
Version <
2.6.18
Status
unaffected
Version <=
5.10.*
Version
5.10.261
Status
unaffected
Version <=
5.15.*
Version
5.15.212
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.4
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.029 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/6253dfee5afba536bb54fc6fe6c091c3758fafe1
https://git.kernel.org/stable/c/65bf0d2b6e914f1448d6a2fde193dcf60936a651
https://git.kernel.org/stable/c/de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf
https://git.kernel.org/stable/c/138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2
https://git.kernel.org/stable/c/83b17872e3166c295c599279fc9562ac3840c638
https://git.kernel.org/stable/c/497c6bae5167428596575f20af6613ff5671f383
https://git.kernel.org/stable/c/dfd1894cb64cbd8758b461ed713800fe73db4f82
https://git.kernel.org/stable/c/6255da28d4bb5349fe18e84cb043ccd394eba75d