Executive brief
A race condition vulnerability was identified in the Linux kernel's handling of process information within the /proc file system. This flaw could potentially allow a local attacker to bypass security checks when accessing file descriptor links of other processes. Successful exploitation could lead to unauthorized access to sensitive process information or file paths, though it typically requires local system access.
Technical details
A race condition exists in proc_pid_get_link() and proc_pid_readlink() within the Linux kernel's procfs implementation. The vulnerability stems from the functions performing a task lookup via PID, executing a ptrace_may_access() check, and then performing a second task lookup to complete the access. This double-lookup pattern is non-atomic, allowing the task state or identity to change between the permission check and the actual access. The fix introduces a new helper, call_proc_get_link(), which utilizes exec_update_lock to ensure the task remains stable and the access check is synchronized with the subsequent operation. This issue affects the /proc/<pid>/fd/ symlinks and related path resolution logic.
Affected products
- Linux Linux Kernel 2.6.18 to 6.13
Timeline
- 2026-07-16: patched: Initial fix authored by Jann Horn
- 2026-07-25: disclosed: CVE-2026-64375 published
References
- https://git.kernel.org/stable/c/138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2
- https://git.kernel.org/stable/c/497c6bae5167428596575f20af6613ff5671f383
- https://git.kernel.org/stable/c/6253dfee5afba536bb54fc6fe6c091c3758fafe1
- https://git.kernel.org/stable/c/6255da28d4bb5349fe18e84cb043ccd394eba75d
- https://git.kernel.org/stable/c/65bf0d2b6e914f1448d6a2fde193dcf60936a651
- https://git.kernel.org/stable/c/83b17872e3166c295c599279fc9562ac3840c638
- https://git.kernel.org/stable/c/de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf