cve-2026-64111
HIGH CVSS 7.1 opencve
Description
In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write() already does before calling the LSM hook. This only matters for SELinux and AppArmor which check whether the process is being ptraced and if so, whether to allow the transition.
Timeline
- Published
- 2026-07-19 16:17 UTC
- Last Modified
- 2026-08-12
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
mitre | ||
| 3.1 | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
nvd | ||
| 3.1 | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
opencve | ||
| 3.1 | 7.0 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
redhat |
References
No references available.
Linked Vulnerabilities
{
"advisories": [
{
"id": "USN-8593-1",
"source": "usn",
"title": "Linux kernel vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8593-1"
},
{
"id": "USN-8603-1",
"source": "usn",
"title": "Linux kernel (Azure) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8603-1"
},
{
"id": "USN-8618-1",
"source": "usn",
"title": "Linux kernel vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8618-1"
},
{
"id": "USN-8663-1",
"source": "usn",
"title": "Linux kernel (NVIDIA) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8663-1"
},
{
"id": "USN-8664-1",
"source": "usn",
"title": "Linux kernel (NVIDIA BaseOS) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8664-1"
},
{
"id": "USN-8728-1",
"source": "usn",
"title": "Linux kernel (GCP) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8728-1"
},
{
"id": "USN-8729-1",
"source": "usn",
"title": "Linux kernel vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8729-1"
},
{
"id": "USN-8761-1",
"source": "usn",
"title": "Linux kernel (Azure) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8761-1"
},
{
"id": "USN-8729-2",
"source": "usn",
"title": "Linux kernel (Raspberry Pi Real-time) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8729-2"
},
{
"id": "USN-8761-2",
"source": "usn",
"title": "Linux kernel (Azure FIPS) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8761-2"
},
{
"id": "USN-8781-1",
"source": "usn",
"title": "Linux kernel (NVIDIA Tegra) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8781-1"
},
{
"id": "USN-8729-3",
"source": "usn",
"title": "Linux kernel vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8729-3"
},
{
"id": "USN-8802-1",
"source": "usn",
"title": "Linux kernel (Oracle) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8802-1"
},
{
"id": "USN-8728-2",
"source": "usn",
"title": "Linux kernel (Azure) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8728-2"
},
{
"id": "USN-8729-4",
"source": "usn",
"title": "Linux kernel (Low Latency) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8729-4"
},
{
"id": "USN-8729-5",
"source": "usn",
"title": "Linux kernel (AWS FIPS) vulnerabilities",
"url": "https://ubuntu.com/security/notices/USN-8729-5"
}
],
"cve": "CVE-2026-64111",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "code_commit",
"value": "[a04a1198088a1378d0389c250cc684f649bcc91e,82d3acee88593e3d9e71cad4b7d6b3cf70de9d07)"
}
},
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "code_commit",
"value": "[a04a1198088a1378d0389c250cc684f649bcc91e,5b906f31e977286888a9e31282589b545b249139)"
}
},
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "code_commit",
"value": "[a04a1198088a1378d0389c250cc684f649bcc91e,a010cadaf5727b8417f62fe9021fcef14a5f9b51)"
}
},
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "code_commit",
"value": "[a04a1198088a1378d0389c250cc684f649bcc91e,4a9b16541ad3faf8bccb398532bf3f8b6bbf1188)"
}
}
],
"enrichment": {
"confidence": 99.0,
"confidence_source": "inferred",
"scores": [
{
"score": 99.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Linux",
"source": "cna",
"vendor": "Linux"
},
"product": "linux_kernel",
"vendor": "linux"
},
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "6.8"
}
},
{
"platform": null,
"status": "unaffected",
"versions": {
"scheme": "generic",
"value": "[0,6.8)"
}
},
{
"platform": null,
"status": "unaffected",
"versions": {
"scheme": "semver",
"value": "[6.12.92,6.13.0)"
}
},
{
"platform": null,
"status": "unaffected",
"versions": {
"scheme": "semver",
"value": "[6.18.34,6.19.0)"
}
},
{
"platform": null,
"status": "unaffected",
"versions": {
"scheme": "semver",
"value": "[7.0.11,7.1.0)"
}
},
{
"platform": null,
"status": "unaffected",
"versions": {
"scheme": "generic",
"value": "[7.1,*]"
}
}
],
"enrichment": {
"confidence": 99.0,
"confidence_source": "inferred",
"scores": [
{
"score": 99.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Linux",
"source": "cna",
"vendor": "Linux"
},
"product": "linux_kernel",
"vendor": "linux"
}
],
"created": "2026-07-21T10:45:02.435833+00:00",
"updated": "2026-08-13T13:00:04.983917+00:00",
"vendors": [
"linux",
"linux$PRODUCT$linux_kernel"
]
},
"epss": {
"score": 0.00171
},
"mitre": {
"cpes": [
"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
],
"created": "2026-07-19T15:40:13.007000+00:00",
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nlsm: hold cred_guard_mutex for lsm_set_self_attr()\n\nJust as proc_pid_attr_write() already does before calling the LSM\nhook. This only matters for SELinux and AppArmor which check\nwhether the process is being ptraced and if so, whether to\nallow the transition.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.1,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/64xxx/CVE-2026-64111.json",
"references": [
"https://git.kernel.org/stable/c/4a9b16541ad3faf8bccb398532bf3f8b6bbf1188",
"https://git.kernel.org/stable/c/5b906f31e977286888a9e31282589b545b249139",
"https://git.kernel.org/stable/c/82d3acee88593e3d9e71cad4b7d6b3cf70de9d07",
"https://git.kernel.org/stable/c/a010cadaf5727b8417f62fe9021fcef14a5f9b51"
],
"title": "lsm: hold cred_guard_mutex for lsm_set_self_attr()",
"updated": "2026-08-05T12:39:20.048000+00:00",
"vendors": [
"linux",
"linux$PRODUCT$linux_kernel"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*"
],
"created": "2026-07-19T16:17:52.463000+00:00",
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nlsm: hold cred_guard_mutex for lsm_set_self_attr()\n\nJust as proc_pid_attr_write() already does before calling the LSM\nhook. This only matters for SELinux and AppArmor which check\nwhether the process is being ptraced and if so, whether to\nallow the transition.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.1,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-64111.json",
"references": [
"https://git.kernel.org/stable/c/4a9b16541ad3faf8bccb398532bf3f8b6bbf1188",
"https://git.kernel.org/stable/c/5b906f31e977286888a9e31282589b545b249139",
"https://git.kernel.org/stable/c/82d3acee88593e3d9e71cad4b7d6b3cf70de9d07",
"https://git.kernel.org/stable/c/a010cadaf5727b8417f62fe9021fcef14a5f9b51"
],
"title": null,
"updated": "2026-08-12T15:50:39.560000+00:00",
"vendors": [
"linux",
"linux$PRODUCT$linux_kernel"
],
"weaknesses": [
"NVD-CWE-noinfo"
]
},
"opencve": {
"changes": [
{
"created": "2026-07-19T16:15:00+00:00",
"data": [
{
"details": {
"new": "In the Linux kernel, the following vulnerability has been resolved:\n\nlsm: hold cred_guard_mutex for lsm_set_self_attr()\n\nJust as proc_pid_attr_write() already does before calling the LSM\nhook. This only matters for SELinux and AppArmor which check\nwhether the process is being ptraced and if so, whether to\nallow the transition.",
"old": null
},
"type": "description"
},
{
"details": {
"new": "lsm: hold cred_guard_mutex for lsm_set_self_attr()",
"old": null
},
"type": "title"
},
{
"details": [
"linux",
"linux$PRODUCT$linux_kernel"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"linux",
"linux$PRODUCT$linux_kernel"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://git.kernel.org/stable/c/4a9b16541ad3faf8bccb398532bf3f8b6bbf1188",
"https://git.kernel.org/stable/c/5b906f31e977286888a9e31282589b545b249139",
"https://git.kernel.org/stable/c/82d3acee88593e3d9e71cad4b7d6b3cf70de9d07",
"https://git.kernel.org/stable/c/a010cadaf5727b8417f62fe9021fcef14a5f9b51"
],
"removed": []
},
"type": "references"
}
],
"id": "bf93d3d6-c46c-48df-9e9f-f2198f341413"
},
{
"created": "2026-07-20T14:45:00+00:00",
"data": [
{
"details": {
"added": {
"cvssV3_1": {
"score": 7.1,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "43286eb9-1475-415f-955a-2b42b386afb1"
},
{
"created": "2026-07-21T12:15:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-412"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"https://lore.kernel.org/linux-cve-announce/2026071922-CVE-2026-64111-6b23@gregkh/T",
"https://nvd.nist.gov/vuln/detail/CVE-2026-64111",
"https://www.cve.org/CVERecord?id=CVE-2026-64111"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {},
"removed": {},
"updated": {
"threat_severity": {
"new": "Moderate",
"old": null
}
}
},
"type": "metrics"
}
],
"id": "734af0fe-6aa1-4e2d-85c7-c7b316931690"
},
{
"created": "2026-07-21T22:15:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-852"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "945f5ce7-cf4e-4bdf-8b6a-f325983c8b2f"
},
{
"created": "2026-07-26T08:15:00+00:00",
"data": [
{
"details": {
"added": [],
"removed": [
"CWE-852"
]
},
"type": "weaknesses"
}
],
"id": "94bdae53-09c8-4544-b3b1-b03a78a0c281"
},
{
"created": "2026-08-12T16:00:00+00:00",
"data": [
{
"details": {
"added": [
"NVD-CWE-noinfo"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
}
],
"id": "6a298f0b-2c0d-48c0-aa6c-ff7b81c59bb4"
}
],
"cpes": {
"data": [
"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-07-19T00:00:00+00:00",
"provider": "redhat"
},
"description": {
"data": "In the Linux kernel, the following vulnerability has been resolved:\n\nlsm: hold cred_guard_mutex for lsm_set_self_attr()\n\nJust as proc_pid_attr_write() already does before calling the LSM\nhook. This only matters for SELinux and AppArmor which check\nwhether the process is being ptraced and if so, whether to\nallow the transition.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 7.1,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00171
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {},
"provider": null
},
"threat_severity": {
"data": "Moderate",
"provider": "redhat"
}
},
"references": {
"data": [
"https://git.kernel.org/stable/c/4a9b16541ad3faf8bccb398532bf3f8b6bbf1188",
"https://git.kernel.org/stable/c/5b906f31e977286888a9e31282589b545b249139",
"https://git.kernel.org/stable/c/82d3acee88593e3d9e71cad4b7d6b3cf70de9d07",
"https://git.kernel.org/stable/c/a010cadaf5727b8417f62fe9021fcef14a5f9b51",
"https://lore.kernel.org/linux-cve-announce/2026071922-CVE-2026-64111-6b23@gregkh/T",
"https://nvd.nist.gov/vuln/detail/CVE-2026-64111",
"https://www.cve.org/CVERecord?id=CVE-2026-64111"
],
"providers": [
"mitre",
"nvd",
"redhat"
]
},
"title": {
"data": "lsm: hold cred_guard_mutex for lsm_set_self_attr()",
"provider": "mitre"
},
"updated": {
"data": "2026-08-12T15:50:39.560000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"linux",
"linux$PRODUCT$linux_kernel"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-412",
"NVD-CWE-noinfo"
],
"providers": [
"nvd",
"redhat"
]
}
},
"redhat": {
"cpes": [],
"created": "2026-07-19T00:00:00+00:00",
"description": "In the Linux kernel, the following vulnerability has been resolved:\nlsm: hold cred_guard_mutex for lsm_set_self_attr()\nJust as proc_pid_attr_write() already does before calling the LSM\nhook. This only matters for SELinux and AppArmor which check\nwhether the process is being ptraced and if so, whether to\nallow the transition.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.0,
"vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"threat_severity": "Moderate"
},
"redhat_repo_path": "2026/CVE-2026-64111.json",
"references": [
"https://lore.kernel.org/linux-cve-announce/2026071922-CVE-2026-64111-6b23@gregkh/T",
"https://nvd.nist.gov/vuln/detail/CVE-2026-64111",
"https://www.cve.org/CVERecord?id=CVE-2026-64111"
],
"title": "kernel: lsm: hold cred_guard_mutex for lsm_set_self_attr()",
"updated": "2026-07-19T00:00:00+00:00",
"vendors": [],
"weaknesses": [
"CWE-412"
]
}
}
Enrichment data
Aggregated bundle (all enrichments)