Executive brief
The Linux kernel's pidfd interface for retrieving namespace file descriptors contains a race condition that allows an attacker to bypass access controls. A process with insufficient privileges can pass an access check against a target's old credentials, then obtain namespace information after the target has executed a setuid binary with new credentials—gaining access to namespaces it should have been denied. This enables unauthorized inspection or manipulation of process isolation boundaries.
Technical details
The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition in the PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() (fs/pidfs.c). The code performs a ptrace access check and namespace lookup without holding the target task's exec_update_lock, unlike the equivalent procfs functions (proc_ns_get_link and proc_ns_readlink). An attacker can pass the ptrace credential check, then exploit a concurrent execve() of a setuid binary by the target to access namespace information after the target's credentials are elevated, bypassing the original access decision. The fix holds exec_update_lock for reading around both the ptrace check and namespace lookup to ensure credentials remain consistent throughout. No exploits in the wild have been reported; the vulnerability was resolved upstream with proper locking semantics.
Affected products
- Linux Linux kernel Affected in versions from 5b08bd408534 (pidfs: allow retrieval of namespace file descriptors) onwards; fixed in upstream commit 9688a46802939da28f00cb40e8129615d5d4af39
Timeline
- 2026-07-31: other: Patch authored by Chen Linxuan
- 2026-08-12: patched: Upstream commit 9688a46802939da28f00cb40e8129615d5d4af39 merged
- 2026-09-11: disclosed