In the Linux kernel, the following vulnerability has been resolved:
audit: fix incorrect inheritable capability in CAPSET records
__audit_log_capset() records the effective capability set into the
inheritable field due to a copy-paste error. Every CAPSET audit
record therefore reports cap_pi (process inheritable) with the value
of cap_effective instead of cap_inheritable.
This silently corrupts audit data used for compliance and forensic
analysis: an attacker who modifies inheritable capabilities to
prepare for a privilege-escalating exec would have the change masked
in the audit trail.
The bug has been present since the original introduction of CAPSET
audit records in 2008.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-26 20:17
Updated : 2026-07-08 03:54
NVD link : CVE-2026-53287
Mitre link : CVE-2026-53287
CVE.ORG link : CVE-2026-53287
JSON object : View
Products Affected
linux
- linux_kernel
CWE
