๐Ÿ” CVE Alert

CVE-2026-80928

HIGH 7.8

smack: fix cred UAF in smack_file_send_sigiotask()

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a non-current task is forbidden unless that task is being created or destroyed; a task is allowed to change its own ->cred pointer with no synchronization, and changing ->cred should only affect the current syscall. smack_file_send_sigiotask() was accessing both sets of credentials: First tsk->cred, then __task_cred(tsk). Fix it, always access the objective credentials here. I have tested that this bug can lead to a KASAN-reported UAF of struct cred in smack_file_send_sigiotask(), and that this fix prevents the race.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
3b11a1decef07c19443d24ae926982bc8ec9f4c0 < a512366d84e134a9eefc2cc40eeb6e80e2ec162c 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < 7c7fe043f3099d0d35002b248967f75e55345b93 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < f9c7b1f2b9d8f4176d2632743f51400855978ace 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < b5bcf3adfa27279da4401ab8f1e1a706601a92be 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < ed64aa505875a3b4defd504ee8e59e1949246a62 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < b791401bf389a1546a830d2b381ca60fe94c7870 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < fedc88e38ce979a720cd2de042578cb5df3dc8de
Linux / Linux
2.6.29

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a512366d84e134a9eefc2cc40eeb6e80e2ec162c git.kernel.org: https://git.kernel.org/stable/c/7c7fe043f3099d0d35002b248967f75e55345b93 git.kernel.org: https://git.kernel.org/stable/c/f9c7b1f2b9d8f4176d2632743f51400855978ace git.kernel.org: https://git.kernel.org/stable/c/b5bcf3adfa27279da4401ab8f1e1a706601a92be git.kernel.org: https://git.kernel.org/stable/c/ed64aa505875a3b4defd504ee8e59e1949246a62 git.kernel.org: https://git.kernel.org/stable/c/b791401bf389a1546a830d2b381ca60fe94c7870 git.kernel.org: https://git.kernel.org/stable/c/fedc88e38ce979a720cd2de042578cb5df3dc8de