Improper access control in Linux kernel - CVE-2026-80596
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access control in the ims-pcu sysfs attribute handlers when accessing sysfs attributes through a non-control interface. A local user can access exposed sysfs attributes on a secondary data interface to cause a denial of service.
The issue occurs because the driver exposes device attributes on all interfaces bound to the driver, even though only the primary control interface has the required descriptors and internal state.