{"id":"CVE-2026-80928","title":"kernel: smack: fix cred UAF in smack_file_send_sigiotask() (CVE-2026-80928)","summary":"A flaw was found in the Linux kernel's SMACK (Simplified Mandatory Access Control Kernel) security module. Incorrect handling of task credentials within the smack_file_send_sigiotask() function can lead to a Use-After-Free (UAF) vulnerabil…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-825","vendor":"Red Hat","product":"Linux","affected":["Linux >= 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < a512366d84e134a9eefc2cc40eeb6e80e2ec162c","Linux >= 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < 7c7fe043f3099d0d35002b248967f75e55345b93","Linux >= 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < f9c7b1f2b9d8f4176d2632743f51400855978ace","Linux >= 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < b5bcf3adfa27279da4401ab8f1e1a706601a92be","Linux >= 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < ed64aa505875a3b4defd504ee8e59e1949246a62","Linux >= 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < b791401bf389a1546a830d2b381ca60fe94c7870","Linux >= 3b11a1decef07c19443d24ae926982bc8ec9f4c0 < fedc88e38ce979a720cd2de042578cb5df3dc8de","Linux 2.6.29"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T13:53:59+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80928.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80928.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80928"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532381"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80928"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80928"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80928.mbox"},{"url":"https://git.kernel.org/stable/c/a512366d84e134a9eefc2cc40eeb6e80e2ec162c"},{"url":"https://git.kernel.org/stable/c/7c7fe043f3099d0d35002b248967f75e55345b93"},{"url":"https://git.kernel.org/stable/c/f9c7b1f2b9d8f4176d2632743f51400855978ace"},{"url":"https://git.kernel.org/stable/c/b5bcf3adfa27279da4401ab8f1e1a706601a92be"},{"url":"https://git.kernel.org/stable/c/ed64aa505875a3b4defd504ee8e59e1949246a62"},{"url":"https://git.kernel.org/stable/c/b791401bf389a1546a830d2b381ca60fe94c7870"},{"url":"https://git.kernel.org/stable/c/fedc88e38ce979a720cd2de042578cb5df3dc8de"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00129,"epssPercentile":0.02909,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.455Z","slug":"CVE-2026-80928","body":"## Overview\n\nA flaw was found in the Linux kernel's SMACK (Simplified Mandatory Access Control Kernel) security module. Incorrect handling of task credentials within the smack_file_send_sigiotask() function can lead to a Use-After-Free (UAF) vulnerability. A local attacker could exploit this flaw to potentially escalate their privileges or disclose sensitive information by manipulating the timing of credential access.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80928.json)\n\n**kernel: smack: fix cred UAF in smack_file_send_sigiotask()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":202779,"id":"CVE-2026-80928","ts":1789403715875,"field":"cvss","old":"7.8","new":"5.5"},{"seq":202778,"id":"CVE-2026-80928","ts":1789403715875,"field":"severity","old":"high","new":"medium"},{"seq":183635,"id":"CVE-2026-80928","ts":1789356676199,"field":"cvss","old":"7.8","new":"7"},{"seq":153108,"id":"CVE-2026-80928","ts":1789285349037,"field":"cvss","old":null,"new":"7.8"},{"seq":153107,"id":"CVE-2026-80928","ts":1789285349037,"field":"severity","old":"none","new":"high"},{"seq":147301,"id":"CVE-2026-80928","ts":1789270208223,"field":"cvss","old":null,"new":"7"},{"seq":147300,"id":"CVE-2026-80928","ts":1789270208223,"field":"severity","old":"none","new":"high"},{"seq":109052,"id":"CVE-2026-80928","ts":1789183730120,"field":"cvss","old":null,"new":"7"},{"seq":109051,"id":"CVE-2026-80928","ts":1789183730120,"field":"severity","old":"none","new":"high"}]}