Junglewise Threat Intelligence

CVE-2026-74676: Linux kernel authorization bypass in KDSKBMETA ioctl

CVE-2026-74676 · Severity: info · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's virtual terminal (vt) driver handles keyboard input and configuration for terminal sessions. A missing permission check in the KDSKBMETA ioctl allows an unprivileged process to modify keyboard meta mode settings on any console without proper authorization. This could enable privilege escalation or disruption of keyboard behavior for other users.

Technical details

The vulnerability is an authorization bypass (missing access control check) in the vt_k_ioctl() function within drivers/tty/vt/vt_ioctl.c. The KDSKBMETA ioctl handler fails to enforce a permission (!perm) check that all other keyboard setter ioctls in the same function properly validate. This allows a process without controlling terminal privileges to invoke the ioctl and modify keyboard meta mode. The fix adds a simple permission check (if (!perm) return -EPERM;) before calling vt_do_kdskbmeta(). No CVSS score or evidence of active exploitation was reported.

Affected products

  • Linux Linux kernel multiple versions (patch backported to 2.6.11 through 7.2)

Timeline

  • 2026-08-22: disclosed
  • 2026-08-19: patched: commit 1c5b67a1e2cb7d78dab321280f330b056e3bf437 and 4671c3b79e337bbae28c2d79023dc642df012bde

References

Related threats