Missing Authorization in Linux kernel - CVE-2026-97564
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a root usermodehelper to process unvetted authority-bearing fields.
The vulnerability exists due to missing authorization validation in cifs.idmap key description handling when invoking request_key(2) with a non-NULL callout. A local user can supply a cifs.idmap key description containing authority-bearing fields to cause a root usermodehelper to process unvetted authority-bearing fields.