Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78408

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 7.9
EPSS Низкий

Описание

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

Отчет

Affected versions: util-linux v2.40 through v2.42.2. The --join-cgroup option was introduced in v2.40; earlier releases (including util-linux 2.38) are not affected. Fixed in v2.41.6 and v2.42.3.

Меры по смягчению последствий

Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not run nsenter --join-cgroup (including nsenter --target PID --all --join-cgroup) against untrusted processes or namespaces. The fix closes the cgroup.procs descriptor immediately after joining, and opens it with O_CLOEXEC.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10util-linuxAffected
Red Hat Enterprise Linux 7util-linuxNot affected
Red Hat Enterprise Linux 8util-linuxNot affected
Red Hat Enterprise Linux 9rhel8/flatpak-runtimeNot affected
Red Hat Enterprise Linux 9rhel8/flatpak-sdkNot affected
Red Hat Enterprise Linux 9util-linuxNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imagesutil-linux-main-2.42.2-3.4.hum1FixedRHSA-2026:6316203.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-775
https://bugzilla.redhat.com/show_bug.cgi?id=2522497util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority

EPSS

Процентиль: 2%
0.00113
Низкий

7.9 High

CVSS3

Связанные уязвимости

CVSS3: 7.9
ubuntu
15 дней назад

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

CVSS3: 7.9
nvd
15 дней назад

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

msrc
11 дней назад

Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority

CVSS3: 7.9
debian
15 дней назад

The nsenter --join-cgroup option opens the target cgroup.procs file as ...

EPSS

Процентиль: 2%
0.00113
Низкий

7.9 High

CVSS3

Уязвимость CVE-2026-78408