Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel - CVE-2026-89766
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose namespace information.
The vulnerability exists due to a time-of-check time-of-use race condition in pidfd_ioctl() when performing PIDFD_GET_*_NAMESPACE ioctls while a target task executes a setuid binary. A local user can race a namespace ioctl with the target task's execve operation to disclose namespace information.