CVE-2026-80663
Last modified
CVE-2026-80663 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: tools/power/x86/intel-speed-select: Harden daemon pidfile open Avoid symlink-based pidfile clobbering by opening the pidfile with O_NOFOLLOW and validating it with fstat() before locking/writing. The daemon currently uses a fixed pidfile path under /tmp. A local unprivileged user can pre-create a symlink at that path and cause a root-run daemon instance to write into an attacker-chosen file.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: tools/power/x86/intel-speed-select: Harden daemon pidfile open Avoid symlink-based pidfile clobbering by opening the pidfile with O_NOFOLLOW and validating it with fstat() before locking/writing. The daemon currently uses a fixed pidfile path under /tmp. A local unprivileged user can pre-create a symlink at that path and cause a root-run daemon instance to write into an attacker-chosen file.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 7fd786dfbd2c55ddee3b87f33c82f1c58bdb1dd6, < 905493a6338c82a70da16f86e0a6215db5a3d73d; >= 7fd786dfbd2c55ddee3b87f33c82f1c58bdb1dd6, < db938eb9a3c1317596c28e94413b33426508d51b; >= 7fd786dfbd2c55ddee3b87f33c82f1c58bdb1dd6, < 72a07abc6b9046f07a08bba353cad7667bcc9dce; >= 7fd786dfbd2c55ddee3b87f33c82f1c58bdb1dd6, < 19ffeb30fdfce63f8d6aca71bcdddb3f69d46278; >= 7fd786dfbd2c55ddee3b87f33c82f1c58bdb1dd6, < e8adac69d1bdf035ef97cc914e845acd4ef08e28; >= 7fd786dfbd2c55ddee3b87f33c82f1c58bdb1dd6, < 607af438e6430893a822964c841a1994b33acccc |
| Linux | Linux | 5.18 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80663?
How severe is CVE-2026-80663?
How do I fix CVE-2026-80663?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80657In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80658In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80659In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80660In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80661In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80662In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-80664In the Linux kernel, the following vulnerability has been re…7.3
- CVE-2026-80665In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-80666In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80667In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80668In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-80669In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-80663?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
