Improper locking in Linux kernel - CVE-2026-97971
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper reference count handling in legitimize_ns() in kernel/nstree.c when processing namespace listing requests. A local user can invoke listns for a namespace they are not permitted to list to compromise confidentiality, integrity, and availability.