Answer in brief
CVE-2026-80928 records a Unknown severity vulnerability in smack: fix cred UAF in smack_file_send_sigiotask(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b5bcf3adfa27279da4401ab8f1e1a706601a92be || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ed64aa505875a3b4defd504ee8e59e1949246a62 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b791401bf389a1546a830d2b381ca60fe94c7870 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <fedc88e38ce979a720cd2de042578cb5df3dc8de || >=0 <6.12.109 || >=0 <6.18.50 || >=0 <7.2.4 | b5bcf3adfa27279da4401ab8f1e1a706601a92be, ed64aa505875a3b4defd504ee8e59e1949246a62, b791401bf389a1546a830d2b381ca60fe94c7870, fedc88e38ce979a720cd2de042578cb5df3dc8de, 6.12.109, 6.18.50, 7.2.4 |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a non-current task is forbidden unless that task is being created or destroyed; a task is allowed to change its own ->cred pointer with no synchronization, and changing ->cred should only affect the current syscall. smack_file_send_sigiotask() was accessing both sets of credentials: First tsk->cred, then __task_cred(tsk). Fix it, always access the objective credentials here. I have tested that this bug can lead to a KASAN-reported UAF of struct cred in smack_file_send_sigiotask(), and that this fix prevents the race.
Quoted source text, attributed separately from HOL analysis.