Executive brief
The Linux kernel's time namespace feature allows container processes to have isolated time views. A missing validation in the proc_timens_set_offset() function fails to check that nanosecond values fall within the valid range (0–999,999,999), potentially allowing incorrect time calculations or unexpected behavior when setting time offsets through /proc/pid/timens_offsets.
Technical details
The vulnerability is an input validation flaw in kernel/time/namespace.c. The proc_timens_set_offset() function validates the tv_sec field but omits validation of the tv_nsec field before passing both to timespec64_add(). The timespec64_add() helper expects normalized timespec64 structures with tv_nsec in the range [0, NSEC_PER_SEC-1]. An attacker or process with write access to /proc/pid/timens_offsets can supply an invalid tv_nsec value (negative or ≥ 1,000,000,000), leading to incorrect time calculations or undefined behavior. The fix adds a simple range check: if (off->val.tv_nsec < 0 || off->val.tv_nsec >= NSEC_PER_SEC) return -EINVAL. No authentication bypass, network attack, or privilege escalation is known; the vulnerability requires local write access to procfs.
Affected products
- Linux Linux kernel versions with time namespace support (4.15+, likely from introduction in commit 04a8682a71be)
Timeline
- 2026-07-04: disclosed: Patch authored by Malaya Kumar Rout
- 2026-07-07: patched: Merged into mainline (commit 06aba58e58492d2b8eae059274caed29025ea96e)
- 2026-09-17: advisory: CVE-2026-93146 published