From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F0F10424D46 for ; Fri, 11 Sep 2026 19:45:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789155962; cv=none; b=P2VQ69dbXJC++dOUoAywh9At3vGfQqgSu6R8GIbz5NMUr7brq4xItkAFrqLtpFNEl8BR72CYvEJ+iMhEHckvNhEPCegGp1XDiVaUNgGntYCwbFDMghIlpI+NM3yaVwam/Lx0fgM7aggtGIiPmfmLu/L+/PVvfiYtvswwkYVrRgQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789155962; c=relaxed/simple; bh=q92OuGx/bUsCBvdPEmD4J/P9y9cA7YW/YxUBNFGLvNc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=rr3N6j4oz5w7gxXOpy1XI+cWh+6DzrQO5TVM70kR1UpnW63mHcWNe2Apm3+k+XeoNbOT9aGWqfQlNr5wviQLmvj/xeIdo8gE5rwJlMCg/91Kl6mTTiW1CU7Mh614E5ntzH1r6V+bcdsfJLCQn0iOpzdgD+R+mZVSWvO/Kkx+m68= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=SGcKyNf1; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="SGcKyNf1" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 581E51F000FF; Fri, 11 Sep 2026 19:45:47 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789155947; bh=+/bgvndixFF8gFNFIhqEdC2vLSJijBXoZGrtr6i455g=; h=From:To:Cc:Subject:Date:Reply-To; b=SGcKyNf1j+TT6rlWz8x4B+OsqVBzT0ikaWiVWFmBBL9kYfNkkHrR2QRXQE3pk61d6 yE5YRCFIc9wGJAI5v29AU//uyaM5pttDrVD96BfmfZEzkHizftMX+p+YK9KkZ1vSRO 6GehWEj2Oi9h1j9FH2GuHg6wCfedvCiwsOVK9MrU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80928: smack: fix cred UAF in smack_file_send_sigiotask() Date: Fri, 11 Sep 2026 21:40:34 +0200 Message-ID: <2026091134-CVE-2026-80928-67e9@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2588; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=GNazX/lKmlYOlcBty3rg9tZ3CsR2c3n+lx0OmKWjva8=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIo0eyu194bTs0431kfKzqmf8/7OMfXGWcvX53LRjk ZULH7Qf7ohlYRBkYpAVU2T5so3n6P6KQ4pehranYeawMoEMYeDiFICJSFsyzFNccZVv4gfHH4wr Q24c3Bl9LbtDqoxhNuuzleFO9Wwf9CXsIqxlt+RqW3PfBQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a non-current task is forbidden unless that task is being created or destroyed; a task is allowed to change its own ->cred pointer with no synchronization, and changing ->cred should only affect the current syscall. smack_file_send_sigiotask() was accessing both sets of credentials: First tsk->cred, then __task_cred(tsk). Fix it, always access the objective credentials here. I have tested that this bug can lead to a KASAN-reported UAF of struct cred in smack_file_send_sigiotask(), and that this fix prevents the race. The Linux kernel CVE team has assigned CVE-2026-80928 to this issue. Affected and fixed versions =========================== Fixed in 6.12.109 with commit b5bcf3adfa27279da4401ab8f1e1a706601a92be Fixed in 6.18.50 with commit ed64aa505875a3b4defd504ee8e59e1949246a62 Fixed in 7.2.4 with commit b791401bf389a1546a830d2b381ca60fe94c7870 Fixed in 7.3-rc1 with commit fedc88e38ce979a720cd2de042578cb5df3dc8de Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80928 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: security/smack/smack_lsm.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/b5bcf3adfa27279da4401ab8f1e1a706601a92be https://git.kernel.org/stable/c/ed64aa505875a3b4defd504ee8e59e1949246a62 https://git.kernel.org/stable/c/b791401bf389a1546a830d2b381ca60fe94c7870 https://git.kernel.org/stable/c/fedc88e38ce979a720cd2de042578cb5df3dc8de