Junglewise Threat Intelligence

CVE-2026-64111: Linux Kernel missing locking in lsm_set_self_attr

CVE-2026-64111 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's security module system. This issue could potentially allow a local user to bypass certain security restrictions enforced by SELinux or AppArmor when a process is being monitored or debugged. This could lead to unauthorized security state transitions on the system.

Technical details

The vulnerability exists in the lsm_set_self_attr() system call within security/lsm_syscalls.c. The function fails to acquire the cred_guard_mutex before calling the security_setselfattr() hook. This mutex is necessary to ensure consistent state when SELinux or AppArmor check if a process is being ptraced during a security transition. A local attacker could potentially exploit this race condition to bypass ptrace-based transition restrictions. The issue has been resolved by ensuring the mutex is held during the attribute update, matching the behavior of proc_pid_attr_write().

Affected products

  • Linux Linux Kernel 6.12.92, 6.18.34, 7.0.11, 7.1

Timeline

  • 2026-07-19: advisory
  • 2026-07-19: disclosed

References

Related threats