« Volver al listado

CVE-2026-80928

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

smack: fix cred UAF in smack_file_send_sigiotask()

When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used.

Accessing ->cred on a non-current task is forbidden unless that task is being created or destroyed; a task is allowed to change its own ->cred pointer with no synchronization, and changing ->cred should only affect the current syscall.

smack_file_send_sigiotask() was accessing both sets of credentials: First tsk->cred, then __task_cred(tsk).

Fix it, always access the objective credentials here.

Leer descripción completaMostrar menos

I have tested that this bug can lead to a KASAN-reported UAF of struct cred in smack_file_send_sigiotask(), and that this fix prevents the race.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local en kernel Linux (AV:L, PR:L) que causa Use-After-Free en credenciales, permitiendo escalada de privilegios o negación de servicio mediante manipulación de memoria.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80928",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3b11a1decef07c19443d24ae926982bc8ec9f4c0",
              "lessThan": "a512366d84e134a9eefc2cc40eeb6e80e2ec162c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3b11a1decef07c19443d24ae926982bc8ec9f4c0",
              "lessThan": "7c7fe043f3099d0d35002b248967f75e55345b93",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3b11a1decef07c19443d24ae926982bc8ec9f4c0",
              "lessThan": "f9c7b1f2b9d8f4176d2632743f51400855978ace",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3b11a1decef07c19443d24ae926982bc8ec9f4c0",
              "lessThan": "b5bcf3adfa27279da4401ab8f1e1a706601a92be",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3b11a1decef07c19443d24ae926982bc8ec9f4c0",
              "lessThan": "ed64aa505875a3b4defd504ee8e59e1949246a62",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3b11a1decef07c19443d24ae926982bc8ec9f4c0",
              "lessThan": "b791401bf389a1546a830d2b381ca60fe94c7870",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3b11a1decef07c19443d24ae926982bc8ec9f4c0",
              "lessThan": "fedc88e38ce979a720cd2de042578cb5df3dc8de",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "security/smack/smack_lsm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.29"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.29",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "security/smack/smack_lsm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:18:56.513",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/7c7fe043f3099d0d35002b248967f75e55345b93",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a512366d84e134a9eefc2cc40eeb6e80e2ec162c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b5bcf3adfa27279da4401ab8f1e1a706601a92be",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b791401bf389a1546a830d2b381ca60fe94c7870",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ed64aa505875a3b4defd504ee8e59e1949246a62",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f9c7b1f2b9d8f4176d2632743f51400855978ace",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fedc88e38ce979a720cd2de042578cb5df3dc8de",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: fix cred UAF in smack_file_send_sigiotask()\n\nWhen inspecting the credentials of another task, objective credentials\n(->real_cred, accessed with __task_cred()) must always be used.\n\nAccessing ->cred on a non-current task is forbidden unless that task is\nbeing created or destroyed; a task is allowed to change its own ->cred\npointer with no synchronization, and changing ->cred should only affect the\ncurrent syscall.\n\nsmack_file_send_sigiotask() was accessing both sets of credentials: First\ntsk->cred, then __task_cred(tsk).\n\nFix it, always access the objective credentials here.\n\nI have tested that this bug can lead to a KASAN-reported UAF of struct cred\nin smack_file_send_sigiotask(), and that this fix prevents the race."
    }
  ],
  "lastModified": "2026-09-14T13:18:49.050",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}