SB20260912228 - Missing Authorization in Linux kernel landlock
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Authorization (CVE-ID: CVE-2026-89560)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass Landlock filesystem access restrictions.
The vulnerability exists due to improper access control in Landlock whiteout creation checks when creating whiteout objects with mknod(2) or renameat2(2) using RENAME_WHITEOUT. A local user can create a whiteout object despite denied required Landlock access rights to bypass Landlock filesystem access restrictions.
Normal renames within layered OverlayFS mounts are not affected.
Remediation
Install update from vendor's website.