Improper access control in Linux kernel - CVE-2026-80675

 

Improper access control in Linux kernel - CVE-2026-80675

Published: August 28, 2026


Vulnerability identifier: #VU146132
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80675
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass metadata integrity validation.

The vulnerability exists due to improper access control in the signed loader metadata map verification logic when validating map metadata hashes for frozen maps. A remote user can load another BPF program with access to the same metadata map to mutate its contents after hash calculation to bypass metadata integrity validation.

Exploitation requires access to a non-exclusive metadata map used by the signed loader.


Affected software

Linux kernel

How to mitigate CVE-2026-80675

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins