SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-80928

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's SMACK (Simplified Mandatory Access Control Kernel) implementation, specifically in the `smack_file_send_sigiotask()` function, where improper access to task credentials can lead to a use-after-free (UAF) condition. This flaw could potentially allow unauthorized access to sensitive information or system resources, posing a security risk for systems relying on the Linux kernel. Organizations using affected Linux distributions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-80928
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a non-current task is forbidden unless that task is being created or destroyed; a task is allowed to change its own ->cred pointer with no synchronization, and changing ->cred should only affect the current syscall. smack_file_send_sigiotask() was accessing both sets of credentials: First tsk->cred, then __task_cred(tsk). Fix it, always access the objective credentials here. I have tested that this bug can lead to a KASAN-reported UAF of struct cred in smack_file_send_sigiotask(), and that this fix prevents the race.