Answer in brief
CVE-2024-42318 records a Unknown severity vulnerability in landlock: Don't lose track of restrictions on cred_transfer. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-42318 records a Unknown severity vulnerability in landlock: Don't lose track of restrictions on cred_transfer. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <916c648323fa53b89eedb34a0988ddaf01406117 || >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <0d74fd54db0bd0c0c224bef0da8fc95ea9c9f36c || >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <16896914bace82d7811c62f3b6d5320132384f49 || >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <b14cc2cf313bd29056fadbc8ecd7f957cf5791ff || >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <39705a6c29f8a2b93cf5b99528a55366c50014d1 | 916c648323fa53b89eedb34a0988ddaf01406117, 0d74fd54db0bd0c0c224bef0da8fc95ea9c9f36c, 16896914bace82d7811c62f3b6d5320132384f49, b14cc2cf313bd29056fadbc8ecd7f957cf5791ff, 39705a6c29f8a2b93cf5b99528a55366c50014d1 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Aug 17, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: landlock: Don't lose track of restrictions on cred_transfer When a process' cred struct is replaced, this _almost_ always invokes the cred_prepare LSM hook; but in one special case (when KEYCTL_SESSION_TO_PARENT updates the parent's credentials), the cred_transfer LSM hook is used instead. Landlock only implements the cred_prepare hook, not cred_transfer, so KEYCTL_SESSION_TO_PARENT causes all information on Landlock restrictions to be lost. This basically means that a process with the ability to use the fork() and keyctl() syscalls can get rid of all Landlock restrictions on itself. Fix it by adding a cred_transfer hook that does the same thing as the existing cred_prepare hook. (Implemented by having hook_cred_prepare() call hook_cred_transfer() so that the two functions are less likely to accidentally diverge in the future.)
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <916c648323fa53b89eedb34a0988ddaf01406117 || >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <0d74fd54db0bd0c0c224bef0da8fc95ea9c9f36c || >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <16896914bace82d7811c62f3b6d5320132384f49 || >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <b14cc2cf313bd29056fadbc8ecd7f957cf5791ff || >=385975dca53eb41031d0cbd1de318eb1bc5d6bb9 <39705a6c29f8a2b93cf5b99528a55366c50014d1 | 916c648323fa53b89eedb34a0988ddaf01406117, 0d74fd54db0bd0c0c224bef0da8fc95ea9c9f36c, 16896914bace82d7811c62f3b6d5320132384f49, b14cc2cf313bd29056fadbc8ecd7f957cf5791ff, 39705a6c29f8a2b93cf5b99528a55366c50014d1 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Aug 17, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: landlock: Don't lose track of restrictions on cred_transfer When a process' cred struct is replaced, this _almost_ always invokes the cred_prepare LSM hook; but in one special case (when KEYCTL_SESSION_TO_PARENT updates the parent's credentials), the cred_transfer LSM hook is used instead. Landlock only implements the cred_prepare hook, not cred_transfer, so KEYCTL_SESSION_TO_PARENT causes all information on Landlock restrictions to be lost. This basically means that a process with the ability to use the fork() and keyctl() syscalls can get rid of all Landlock restrictions on itself. Fix it by adding a cred_transfer hook that does the same thing as the existing cred_prepare hook. (Implemented by having hook_cred_prepare() call hook_cred_transfer() so that the two functions are less likely to accidentally diverge in the future.)
Quoted source text, attributed separately from HOL analysis.