Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel - CVE-2026-89603

 

Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel - CVE-2026-89603

Published: September 12, 2026


Vulnerability identifier: #VU149196
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89603
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute system calls prohibited by a seccomp filter.

The vulnerability exists due to a race condition in syscall_trace_enter() when a thread is stopped for ptrace while another thread installs a seccomp filter with SECCOMP_FILTER_FLAG_TSYNC. A local user can install a seccomp filter with SECCOMP_FILTER_FLAG_TSYNC while another thread is stopped for ptrace to execute system calls prohibited by the filter.

The system call number may be modified during ptrace handling.


Affected software

Linux kernel

How to mitigate CVE-2026-89603

Install security update from vendor's repository.


External References

Related Security Bulletins