Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64111

Опубликовано: 19 июл. 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write() already does before calling the LSM hook. This only matters for SELinux and AppArmor which check whether the process is being ptraced and if so, whether to allow the transition.

A flaw was found in the Linux kernel's Security Module (LSM). A local attacker could exploit this vulnerability by leveraging an improper handling of a credential guard mutex in the lsm_set_self_attr() function. This oversight may allow the attacker to bypass security restrictions enforced by modules such as SELinux and AppArmor when a process is being debugged, potentially leading to unauthorized access or privilege escalation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelFix deferred
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred
Red Hat Hardened Imageserlang27Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-412
https://bugzilla.redhat.com/show_bug.cgi?id=2502490kernel: lsm: hold cred_guard_mutex for lsm_set_self_attr()

EPSS

Процентиль: 3%
0.00135
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
13 дней назад

In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write() already does before calling the LSM hook. This only matters for SELinux and AppArmor which check whether the process is being ptraced and if so, whether to allow the transition.

CVSS3: 7.1
nvd
13 дней назад

In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write() already does before calling the LSM hook. This only matters for SELinux and AppArmor which check whether the process is being ptraced and if so, whether to allow the transition.

msrc
12 дней назад

lsm: hold cred_guard_mutex for lsm_set_self_attr()

CVSS3: 7.1
debian
13 дней назад

In the Linux kernel, the following vulnerability has been resolved: l ...

CVSS3: 7.1
github
13 дней назад

In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write() already does before calling the LSM hook. This only matters for SELinux and AppArmor which check whether the process is being ptraced and if so, whether to allow the transition.

EPSS

Процентиль: 3%
0.00135
Низкий

7 High

CVSS3