Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel - CVE-2026-89603
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to execute system calls prohibited by a seccomp filter.
The vulnerability exists due to a race condition in syscall_trace_enter() when a thread is stopped for ptrace while another thread installs a seccomp filter with SECCOMP_FILTER_FLAG_TSYNC. A local user can install a seccomp filter with SECCOMP_FILTER_FLAG_TSYNC while another thread is stopped for ptrace to execute system calls prohibited by the filter.
The system call number may be modified during ptrace handling.