In the Linux kernel, the following vulnerability has been resolved:
sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
cad_pid is global, and kill_cad_pid() is only used in the root namespace.
However, due to pid_table_root_permissions(), a non-root user can unshare
pid/user namespaces and modify it from the child namespace. This makes no
sense and is simply wrong.
Move it to kern_reboot_table[] where it logically belongs; this ensures
that only GLOBAL_ROOT_UID can read/modify this sysctl.
Note that this patch doesn't preserve "#ifdef CONFIG_PROC_SYSCTL" around
the "cad_pid"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always
set when kern_reboot_table[] is compiled.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-11 20:18
Updated : 2026-09-13 07:17
NVD link : CVE-2026-80929
Mitre link : CVE-2026-80929
CVE.ORG link : CVE-2026-80929
JSON object : View
Products Affected
No product.
CWE
No CWE.
