In the Linux kernel, the following vulnerability has been resolved:
smack: fix bug: unprivileged task can create labels
If an unprivileged task is allowed to relabel itself
(/smack/relabel-self is not empty),
it can freely create new labels by writing their
names into own /proc/PID/attr/smack/current
This occurs because do_setattr() imports
the provided label in advance,
before checking "relabel-self" list.
This change ensures that the "relabel-self" list
is checked before importing the label.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-24 11:16
Updated : 2026-06-17 09:59
NVD link : CVE-2025-68733
Mitre link : CVE-2025-68733
CVE.ORG link : CVE-2025-68733
JSON object : View
Products Affected
No product.
CWE
No CWE.
