SB20260918322 - Protection mechanism failure in Linux kernel arm64 kernel
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Protection mechanism failure (CVE-ID: CVE-2026-90347)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass seccomp and audit checks.
The vulnerability exists due to improper synchronization of the original first syscall argument in arm64 ptrace register and syscall setting code when modifying the first syscall argument during a seccomp ptrace exit. A local user can modify the first syscall argument to bypass seccomp and audit checks.
Remediation
Install update from vendor's website.