Junglewise Threat Intelligence

CVE-2026-89766: Linux kernel pidfd namespace ioctl race condition

CVE-2026-89766 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's pidfd interface for retrieving namespace file descriptors contains a race condition that allows an attacker to bypass access controls. A process with insufficient privileges can pass an access check against a target's old credentials, then obtain namespace information after the target has executed a setuid binary with new credentials—gaining access to namespaces it should have been denied. This enables unauthorized inspection or manipulation of process isolation boundaries.

Technical details

The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition in the PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() (fs/pidfs.c). The code performs a ptrace access check and namespace lookup without holding the target task's exec_update_lock, unlike the equivalent procfs functions (proc_ns_get_link and proc_ns_readlink). An attacker can pass the ptrace credential check, then exploit a concurrent execve() of a setuid binary by the target to access namespace information after the target's credentials are elevated, bypassing the original access decision. The fix holds exec_update_lock for reading around both the ptrace check and namespace lookup to ensure credentials remain consistent throughout. No exploits in the wild have been reported; the vulnerability was resolved upstream with proper locking semantics.

Affected products

  • Linux Linux kernel Affected in versions from 5b08bd408534 (pidfs: allow retrieval of namespace file descriptors) onwards; fixed in upstream commit 9688a46802939da28f00cb40e8129615d5d4af39

Timeline

  • 2026-07-31: other: Patch authored by Chen Linxuan
  • 2026-08-12: patched: Upstream commit 9688a46802939da28f00cb40e8129615d5d4af39 merged
  • 2026-09-11: disclosed

References

Related threats