Improper access control in Linux kernel - CVE-2026-80596

 

Improper access control in Linux kernel - CVE-2026-80596

Published: August 28, 2026


Vulnerability identifier: #VU146283
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80596
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper access control in the ims-pcu sysfs attribute handlers when accessing sysfs attributes through a non-control interface. A local user can access exposed sysfs attributes on a secondary data interface to cause a denial of service.

The issue occurs because the driver exposes device attributes on all interfaces bound to the driver, even though only the primary control interface has the required descriptors and internal state.


Affected software

Linux kernel

How to mitigate CVE-2026-80596

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins