CVE-2026-80929

In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is only used in the root namespace. However, due to pid_table_root_permissions(), a non-root user can unshare pid/user namespaces and modify it from the child namespace. This makes no sense and is simply wrong. Move it to kern_reboot_table[] where it logically belongs; this ensures that only GLOBAL_ROOT_UID can read/modify this sysctl. Note that this patch doesn't preserve "#ifdef CONFIG_PROC_SYSCTL" around the "cad_pid"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always set when kern_reboot_table[] is compiled.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 20:18

Updated : 2026-09-13 07:17


NVD link : CVE-2026-80929

Mitre link : CVE-2026-80929

CVE.ORG link : CVE-2026-80929


JSON object : View

Products Affected

No product.

CWE

No CWE.