SB2026031750 - Insufficient logging in Linux kernel asm-generic



SB2026031750 - Insufficient logging in Linux kernel asm-generic

Published: March 17, 2026

Security Bulletin ID SB2026031750
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficient logging (CVE-ID: CVE-2026-23241)

The vulnerability allows a local user to bypass audit logging for specific file operations.

The vulnerability exists due to improper input validation in the audit subsystem when handling getxattrat() and listxattrat() system calls. A local user can perform extended attribute retrieval operations on files to bypass configured audit rules intended to monitor read, write, and attribute access.

Successful exploitation requires the ability to execute system calls on files with extended attributes and existing audit rules that monitor attribute access. The impact includes reduced audit trail visibility, potentially enabling undetected access to sensitive files.


Remediation

Install update from vendor's website.