proc: protect ptrace_may_access() with exec_update_lock (part 1)
Summary
| CVE | CVE-2026-64371 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-25 10:17:20 UTC |
| Updated | 2026-07-25 10:17:20 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: proc: protect ptrace_may_access() with exec_update_lock (part 1) Fix the easy cases where procfs currently calls ptrace_may_access() without exec_update_lock protection, where the fix is to simply add the extra lock or use mm_access(): - do_task_stat(): grab exec_update_lock - proc_pid_wchan(): grab exec_update_lock - proc_map_files_lookup(): use mm_access() instead of get_task_mm() - proc_map_files_readdir(): use mm_access() instead of get_task_mm() - proc_ns_get_link(): grab exec_update_lock - proc_ns_readlink(): grab exec_update_lock |
Risk And Classification
EPSS: 0.001770000 probability, percentile 0.075050000 (date 2026-07-28)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected f83ce3e6b02d5e48b3a43b001390e2b58820389d ae1e630bcaac739f625822078edbaea98366930d git | Not specified |
| CNA | Linux | Linux | affected f83ce3e6b02d5e48b3a43b001390e2b58820389d d54f14655fd7d7b293698a8b6918563c4c0465e7 git | Not specified |
| CNA | Linux | Linux | affected f83ce3e6b02d5e48b3a43b001390e2b58820389d bb43679356f1f2a4c6b1c88aec4f021e5b5c74e9 git | Not specified |
| CNA | Linux | Linux | affected f83ce3e6b02d5e48b3a43b001390e2b58820389d 7456ae990a9738962b33146916fabca62ae3d4e0 git | Not specified |
| CNA | Linux | Linux | affected f83ce3e6b02d5e48b3a43b001390e2b58820389d 4bfe8c481846cee52473a2f7d7b30ee8e6749fc4 git | Not specified |
| CNA | Linux | Linux | affected f83ce3e6b02d5e48b3a43b001390e2b58820389d f9b4b03ccc9c69bf7f7298d4559906ebea7143b3 git | Not specified |
| CNA | Linux | Linux | affected f83ce3e6b02d5e48b3a43b001390e2b58820389d c1cfd63326f5d09999134e9052c353faf738286e git | Not specified |
| CNA | Linux | Linux | affected f83ce3e6b02d5e48b3a43b001390e2b58820389d 6650527444dadc63d84aa939d14ecba4fadb2f69 git | Not specified |
| CNA | Linux | Linux | affected 6b06d6282100dd5aacf7d45443d651a1995bd9c4 git | Not specified |
| CNA | Linux | Linux | affected 334ed22054b2ec8477e4409e214fc139cf937ef6 git | Not specified |
| CNA | Linux | Linux | affected 2.6.27.23 2.6.28 semver | Not specified |
| CNA | Linux | Linux | affected 2.6.29.3 2.6.30 semver | Not specified |
| CNA | Linux | Linux | affected 2.6.30 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.30 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.261 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.212 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.178 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.145 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.97 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.40 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.4 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/ae1e630bcaac739f625822078edbaea98366930d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4bfe8c481846cee52473a2f7d7b30ee8e6749fc4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7456ae990a9738962b33146916fabca62ae3d4e0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d54f14655fd7d7b293698a8b6918563c4c0465e7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/bb43679356f1f2a4c6b1c88aec4f021e5b5c74e9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c1cfd63326f5d09999134e9052c353faf738286e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6650527444dadc63d84aa939d14ecba4fadb2f69 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f9b4b03ccc9c69bf7f7298d4559906ebea7143b3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.