Executive brief
A vulnerability was identified in the Linux kernel's security module system. This issue could potentially allow a local user to bypass certain security restrictions enforced by SELinux or AppArmor when a process is being monitored or debugged. This could lead to unauthorized security state transitions on the system.
Technical details
The vulnerability exists in the lsm_set_self_attr() system call within security/lsm_syscalls.c. The function fails to acquire the cred_guard_mutex before calling the security_setselfattr() hook. This mutex is necessary to ensure consistent state when SELinux or AppArmor check if a process is being ptraced during a security transition. A local attacker could potentially exploit this race condition to bypass ptrace-based transition restrictions. The issue has been resolved by ensuring the mutex is held during the attribute update, matching the behavior of proc_pid_attr_write().
Affected products
- Linux Linux Kernel 6.12.92, 6.18.34, 7.0.11, 7.1
Timeline
- 2026-07-19: advisory
- 2026-07-19: disclosed