{"id":"CVE-2026-80928","summary":"smack: fix cred UAF in smack_file_send_sigiotask()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: fix cred UAF in smack_file_send_sigiotask()\n\nWhen inspecting the credentials of another task, objective credentials\n(-\u003ereal_cred, accessed with __task_cred()) must always be used.\n\nAccessing -\u003ecred on a non-current task is forbidden unless that task is\nbeing created or destroyed; a task is allowed to change its own -\u003ecred\npointer with no synchronization, and changing -\u003ecred should only affect the\ncurrent syscall.\n\nsmack_file_send_sigiotask() was accessing both sets of credentials: First\ntsk-\u003ecred, then __task_cred(tsk).\n\nFix it, always access the objective credentials here.\n\nI have tested that this bug can lead to a KASAN-reported UAF of struct cred\nin smack_file_send_sigiotask(), and that this fix prevents the race.","modified":"2026-09-18T18:26:39.006433966Z","published":"2026-09-11T19:42:04.044Z","related":["openSUSE-SU-2026:11805-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80928.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/7c7fe043f3099d0d35002b248967f75e55345b93"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a512366d84e134a9eefc2cc40eeb6e80e2ec162c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b5bcf3adfa27279da4401ab8f1e1a706601a92be"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b791401bf389a1546a830d2b381ca60fe94c7870"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ed64aa505875a3b4defd504ee8e59e1949246a62"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f9c7b1f2b9d8f4176d2632743f51400855978ace"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fedc88e38ce979a720cd2de042578cb5df3dc8de"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80928.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80928"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"3b11a1decef07c19443d24ae926982bc8ec9f4c0"},{"fixed":"a512366d84e134a9eefc2cc40eeb6e80e2ec162c"},{"fixed":"7c7fe043f3099d0d35002b248967f75e55345b93"},{"fixed":"f9c7b1f2b9d8f4176d2632743f51400855978ace"},{"fixed":"b5bcf3adfa27279da4401ab8f1e1a706601a92be"},{"fixed":"ed64aa505875a3b4defd504ee8e59e1949246a62"},{"fixed":"b791401bf389a1546a830d2b381ca60fe94c7870"},{"fixed":"fedc88e38ce979a720cd2de042578cb5df3dc8de"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80928.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.29"},{"fixed":"5.15.221"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.109"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80928.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}