Answer in brief
CVE-2026-80929 records a Unknown severity vulnerability in sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e054bcbe7e7af2baad3752f1a4916a7fffc0457e <e8527de7fea191fda704792a56081f9009aeec37 || >=e054bcbe7e7af2baad3752f1a4916a7fffc0457e <a09bc4eaa67e1a72df3b6d0beb3afeef1e1fdfcd || >=e054bcbe7e7af2baad3752f1a4916a7fffc0457e <7170ca01623b399c97f2ae9d3e228badc1f25ea3 | e8527de7fea191fda704792a56081f9009aeec37, a09bc4eaa67e1a72df3b6d0beb3afeef1e1fdfcd, 7170ca01623b399c97f2ae9d3e228badc1f25ea3 |
| Linux/Linuxgeneric | 6.17 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is only used in the root namespace. However, due to pid_table_root_permissions(), a non-root user can unshare pid/user namespaces and modify it from the child namespace. This makes no sense and is simply wrong. Move it to kern_reboot_table[] where it logically belongs; this ensures that only GLOBAL_ROOT_UID can read/modify this sysctl. Note that this patch doesn't preserve "#ifdef CONFIG_PROC_SYSCTL" around the "cad_pid"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always set when kern_reboot_table[] is compiled.
Quoted source text, attributed separately from HOL analysis.