Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-93222

 

Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-93222

Published: September 25, 2026


Vulnerability identifier: #VU152176
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93222
CWE-ID: CWE-668
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause signal sender identifiers to be incorrectly rewritten.

The vulnerability exists due to improper handling of shared siginfo data in the signal delivery logic when delivering group signals across namespaces. A local user can send a group signal to cause sender identifiers rewritten for one recipient to affect subsequent recipients.


Affected software

Linux kernel

How to mitigate CVE-2026-93222

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins