SB20260912174 - Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel syscall_trace_enter()



SB20260912174 - Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel syscall_trace_enter()

Published: September 12, 2026

Security Bulletin ID SB20260912174
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-89603)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute system calls prohibited by a seccomp filter.

The vulnerability exists due to a race condition in syscall_trace_enter() when a thread is stopped for ptrace while another thread installs a seccomp filter with SECCOMP_FILTER_FLAG_TSYNC. A local user can install a seccomp filter with SECCOMP_FILTER_FLAG_TSYNC while another thread is stopped for ptrace to execute system calls prohibited by the filter.

The system call number may be modified during ptrace handling.


Remediation

Install update from vendor's website.