CVE-2026-80928

Source
https://cve.org/CVERecord?id=CVE-2026-80928
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80928.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-80928
Downstream
Related
Published
2026-09-11T19:42:04Z
Modified
2026-09-18T18:26:39Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
smack: fix cred UAF in smack_file_send_sigiotask()
Details

In the Linux kernel, the following vulnerability has been resolved:

smack: fix cred UAF in smack_file_send_sigiotask()

When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used.

Accessing ->cred on a non-current task is forbidden unless that task is being created or destroyed; a task is allowed to change its own ->cred pointer with no synchronization, and changing ->cred should only affect the current syscall.

smack_file_send_sigiotask() was accessing both sets of credentials: First tsk->cred, then __task_cred(tsk).

Fix it, always access the objective credentials here.

I have tested that this bug can lead to a KASAN-reported UAF of struct cred in smack_file_send_sigiotask(), and that this fix prevents the race.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80928.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3b11a1decef07c19443d24ae926982bc8ec9f4c0
Fixed
a512366d84e134a9eefc2cc40eeb6e80e2ec162c
Fixed
7c7fe043f3099d0d35002b248967f75e55345b93
Fixed
f9c7b1f2b9d8f4176d2632743f51400855978ace
Fixed
b5bcf3adfa27279da4401ab8f1e1a706601a92be
Fixed
ed64aa505875a3b4defd504ee8e59e1949246a62
Fixed
b791401bf389a1546a830d2b381ca60fe94c7870
Fixed
fedc88e38ce979a720cd2de042578cb5df3dc8de

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80928.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.29
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80928.json"