Junglewise Threat Intelligence

CVE-2026-93146: Linux kernel input validation bypass in time namespace offset setting

CVE-2026-93146 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's time namespace feature allows container processes to have isolated time views. A missing validation in the proc_timens_set_offset() function fails to check that nanosecond values fall within the valid range (0–999,999,999), potentially allowing incorrect time calculations or unexpected behavior when setting time offsets through /proc/pid/timens_offsets.

Technical details

The vulnerability is an input validation flaw in kernel/time/namespace.c. The proc_timens_set_offset() function validates the tv_sec field but omits validation of the tv_nsec field before passing both to timespec64_add(). The timespec64_add() helper expects normalized timespec64 structures with tv_nsec in the range [0, NSEC_PER_SEC-1]. An attacker or process with write access to /proc/pid/timens_offsets can supply an invalid tv_nsec value (negative or ≥ 1,000,000,000), leading to incorrect time calculations or undefined behavior. The fix adds a simple range check: if (off->val.tv_nsec < 0 || off->val.tv_nsec >= NSEC_PER_SEC) return -EINVAL. No authentication bypass, network attack, or privilege escalation is known; the vulnerability requires local write access to procfs.

Affected products

  • Linux Linux kernel versions with time namespace support (4.15+, likely from introduction in commit 04a8682a71be)

Timeline

  • 2026-07-04: disclosed: Patch authored by Malaya Kumar Rout
  • 2026-07-07: patched: Merged into mainline (commit 06aba58e58492d2b8eae059274caed29025ea96e)
  • 2026-09-17: advisory: CVE-2026-93146 published

References

Related threats