SB20260912228 - Missing Authorization in Linux kernel landlock



SB20260912228 - Missing Authorization in Linux kernel landlock

Published: September 12, 2026

Security Bulletin ID SB20260912228
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Authorization (CVE-ID: CVE-2026-89560)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass Landlock filesystem access restrictions.

The vulnerability exists due to improper access control in Landlock whiteout creation checks when creating whiteout objects with mknod(2) or renameat2(2) using RENAME_WHITEOUT. A local user can create a whiteout object despite denied required Landlock access rights to bypass Landlock filesystem access restrictions.

Normal renames within layered OverlayFS mounts are not affected.


Remediation

Install update from vendor's website.