Executive brief
A security vulnerability was identified in the Linux kernel's namespace file system (nsfs). This flaw could allow a local user or service to view information about other isolated services that should remain private. If exploited, this could lead to information leaks between supposedly separate environments, potentially compromising sensitive system data or operational security.
Technical details
A vulnerability in the Linux kernel's nsfs (namespace filesystem) was discovered where permission checks for namespace iteration ioctls (NS_MNT_GET_NEXT and NS_MNT_GET_PREV) were insufficiently restrictive. This allowed local processes, including some privileged services, to iterate through and potentially leak information from other namespaces they should not have access to. The fix introduces the may_see_all_namespaces() helper to enforce stricter policy, requiring the caller to be in the initial PID namespace and possess CAP_SYS_ADMIN in the initial user namespace. Patches have been released for multiple stable kernel branches including 6.12.y, 6.18.y, and 6.19.y.
Affected products
- Linux Linux Kernel 6.12 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.9, 7.0-rc1, 7.0-rc2
Timeline
- 2026-05-08: advisory: Initial publication of CVE-2026-43403
- 2026-02-26: patched: Initial patch authored by Christian Brauner