CVE-2026-64371

UnknownEPSS 0.18%

Last modified

CVE-2026-64371 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: proc: protect ptrace_may_access() with exec_update_lock (part 1) Fix the easy cases where procfs currently calls ptrace_may_access() without exec_update_lock protection, where the fix is to simply add the extra lock or use mm_access(): - do_task_stat(): grab exec_update_lock - proc_pid_wchan(): grab exec_update_lock - proc_map_files_lookup(): use mm_access() instead of get_task_mm() - proc_map_files_readdir(): use mm_access() instead of get_task_mm() - proc_ns_get_link(): grab exec_update_lock - proc_ns_readlink(): grab exec_update_lock. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: proc: protect ptrace_may_access() with exec_update_lock (part 1) Fix the easy cases where procfs currently calls ptrace_may_access() without exec_update_lock protection, where the fix is to simply add the extra lock or use mm_access(): - do_task_stat(): grab exec_update_lock - proc_pid_wchan(): grab exec_update_lock - proc_map_files_lookup(): use mm_access() instead of get_task_mm() - proc_map_files_readdir(): use mm_access() instead of get_task_mm() - proc_ns_get_link(): grab exec_update_lock - proc_ns_readlink(): grab exec_update_lock

Metrics

EPSS Probability
0.18%

7.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= f83ce3e6b02d5e48b3a43b001390e2b58820389d, < ae1e630bcaac739f625822078edbaea98366930d; >= f83ce3e6b02d5e48b3a43b001390e2b58820389d, < d54f14655fd7d7b293698a8b6918563c4c0465e7; >= f83ce3e6b02d5e48b3a43b001390e2b58820389d, < bb43679356f1f2a4c6b1c88aec4f021e5b5c74e9; >= f83ce3e6b02d5e48b3a43b001390e2b58820389d, < 7456ae990a9738962b33146916fabca62ae3d4e0; >= f83ce3e6b02d5e48b3a43b001390e2b58820389d, < 4bfe8c481846cee52473a2f7d7b30ee8e6749fc4; >= f83ce3e6b02d5e48b3a43b001390e2b58820389d, < f9b4b03ccc9c69bf7f7298d4559906ebea7143b3; >= f83ce3e6b02d5e48b3a43b001390e2b58820389d, < c1cfd63326f5d09999134e9052c353faf738286e; >= f83ce3e6b02d5e48b3a43b001390e2b58820389d, < 6650527444dadc63d84aa939d14ecba4fadb2f69; 6b06d6282100dd5aacf7d45443d651a1995bd9c4; 334ed22054b2ec8477e4409e214fc139cf937ef6; >= 2.6.27.23, < 2.6.28; >= 2.6.29.3, < 2.6.30
LinuxLinux2.6.30

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-64371?
In the Linux kernel, the following vulnerability has been resolved: proc: protect ptrace_may_access() with exec_update_lock (part 1) Fix the easy cases where procfs currently calls ptrace_may_access() without exec_update_lock protection, where the fix is to simply add the extra lock or use mm_access(): - do_task_stat(): grab exec_update_lock - proc_pid_wchan(): grab exec_update_lock - proc_map_files_lookup(): use mm_access() instead of get_task_mm() - proc_map_files_readdir(): use mm_access() instead of get_task_mm() - proc_ns_get_link(): grab exec_update_lock - proc_ns_readlink(): grab exec_update_lock
How severe is CVE-2026-64371?
Severity scoring for CVE-2026-64371 is pending analysis. The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2026-64371?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-64371?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST