Junglewise Threat Intelligence

CVE-2026-59677: SELinux policycoreutils missing authorization in seunshare killall

CVE-2026-59677 · Severity: info · CVSS 6.8 · Published 2026-07-23

Executive brief

A vulnerability in the SELinux 'seunshare' utility, a tool used to run programs in isolated sandboxes, could allow a local user to terminate critical system processes. On systems where users run in an 'unconfined' security context, an attacker could kill processes owned by the root user, such as the SSH daemon. This could lead to a localized denial-of-service, disrupting system operations and administrative access.

Technical details

A Missing Authorization vulnerability (CWE-862) exists in the 'killall()' function of the 'seunshare' utility within SELinux policycoreutils. The utility provides '--kill' and '-Z' flags intended to manage processes within a specific MCS level or SELinux context. However, when a caller is running in an 'unconfined' domain (common in many default 'targeted' policies), the program fails to properly restrict the scope of the kill signal. A local attacker can leverage this to send signals to any process sharing the unconfined context, including those owned by root (e.g., sshd). This issue was addressed in version 3.11 by removing the affected '--kill' functionality.

Affected products

  • SELinuxProject policycoreutils (seunshare) through 3.10

Timeline

  • 2026-06-15: disclosed: Initial discovery and internal reporting at SUSE.
  • 2026-07-02: patched: Upstream release 3.11 removes the vulnerable functionality.
  • 2026-07-15: advisory: SUSE Security Team publishes detailed blog post.
  • 2026-07-23: advisory: CVE-2026-59677 published to NVD.

References