signal: avoid shared siginfo namespace rewrites
Summary
| CVE | CVE-2026-93222 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-24 16:17:17 UTC |
| Updated | 2026-09-24 16:17:17 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
signal: avoid shared siginfo namespace rewrites
send_signal_locked() rewrites sender ids for the target namespace. Group
sends reuse the same siginfo, so one recipient can affect the next.
Copy the siginfo before changing it. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 7a0cf094944e2540758b7f957eb6846d5126f535 e015d1ac6b43a23c52c5163299414ae77d7d4ae0 git |
Not specified |
| CNA |
Linux |
Linux |
affected 7a0cf094944e2540758b7f957eb6846d5126f535 4ee7c4e4719a825052f42f02ec159b5b42b68fbc git |
Not specified |
| CNA |
Linux |
Linux |
affected 7a0cf094944e2540758b7f957eb6846d5126f535 148b0dae2a1755beb873a2aab51fb191414f068c git |
Not specified |
| CNA |
Linux |
Linux |
affected 7a0cf094944e2540758b7f957eb6846d5126f535 6b1de022304ef85284c5933a5fb8492f6f54efc9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 7a0cf094944e2540758b7f957eb6846d5126f535 03c8761e75d1619906bb503686f9cc1dfc6a67f4 git |
Not specified |
| CNA |
Linux |
Linux |
affected 7a0cf094944e2540758b7f957eb6846d5126f535 a246da20c8e4ae4319511c698b9f26ad0ad1769f git |
Not specified |
| CNA |
Linux |
Linux |
affected 7a0cf094944e2540758b7f957eb6846d5126f535 b655c2040ce836afad5643842543567b31f8c11d git |
Not specified |
| CNA |
Linux |
Linux |
affected 7a0cf094944e2540758b7f957eb6846d5126f535 d19cdc167e696714509e87d3f7ae765b6e164589 git |
Not specified |
| CNA |
Linux |
Linux |
affected e897dd22800f02bd48aefb1511fff0b2ce96e94c git |
Not specified |
| CNA |
Linux |
Linux |
affected 2f0e9eed11ca778d0ec5507a739c28472fd4ca20 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.1.20 5.2 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.2.3 5.3 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.3 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.3 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.270 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.221 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.188 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/a246da20c8e4ae4319511c698b9f26ad0ad1769f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/d19cdc167e696714509e87d3f7ae765b6e164589 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6b1de022304ef85284c5933a5fb8492f6f54efc9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/03c8761e75d1619906bb503686f9cc1dfc6a67f4 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/4ee7c4e4719a825052f42f02ec159b5b42b68fbc |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b655c2040ce836afad5643842543567b31f8c11d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e015d1ac6b43a23c52c5163299414ae77d7d4ae0 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/148b0dae2a1755beb873a2aab51fb191414f068c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.