Improper access control in Linux kernel - CVE-2026-64294
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in the mincore() and madvise(MADV_PAGEOUT) ownership checks when handling files on idmapped mounts. A local user can access these interfaces on a crafted idmapped mount to disclose sensitive information.
The issue affects side-channel protection logic and occurs because ownership was checked against an idmap that ignored the file's mount idmap.
Affected software
How to mitigate CVE-2026-64294
External References
- https://git.kernel.org/stable/c/04ba248d02d9eaa3d9077b00a6134caa75fa3e90
- https://git.kernel.org/stable/c/5c942ad7df75925ee166e7f0fb36892d8dde376b
- https://git.kernel.org/stable/c/744b23aa430d52f5c8e4dbff7d71496d6643bed2
- https://git.kernel.org/stable/c/8344bdf0629457e532797b42d9d2bbf2a2900bbf
- https://git.kernel.org/stable/c/e187bc02f8fa4226d62814592cf064ee4557c470