SB2026091233 - Improper access control in Linux kernel debugfs



SB2026091233 - Improper access control in Linux kernel debugfs

Published: September 12, 2026

Security Bulletin ID SB2026091233
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-89745)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass debugfs lockdown protections.

The vulnerability exists due to improper access control in the debugfs lockdown check when accessing a debugfs file that uses mmap_prepare. A local user can use the file's mmap functionality to bypass debugfs lockdown protections.

The issue occurs when the kernel is operating in integrity lockdown mode.


Remediation

Install update from vendor's website.