{"id":"CVE-2026-90347","title":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry\n\nCommit e057b9477232 (\"arm64: syscall: Ensure saved x0 is kept in-sync\nwith tracer updates\") attempted to…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry\n\nCommit e057b9477232 (\"arm64: syscall: Ensure saved x0 is kept in-sync\nwith tracer updates\") attempted to…","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","vendor":"Linux","product":"Linux","affected":["Linux >= a5cd110cb8369d6b37ef5ccfe56b3fa1338c9615 < f433869f23841a50455c4087d85540d5b4d37cde","Linux >= a5cd110cb8369d6b37ef5ccfe56b3fa1338c9615 < 88b839ce497ccb1ff92f7ae742c78dd2937ba572","Linux 4.8"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:17:54.883","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90347","references":[{"url":"https://git.kernel.org/stable/c/88b839ce497ccb1ff92f7ae742c78dd2937ba572","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f433869f23841a50455c4087d85540d5b4d37cde","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00152,"epssPercentile":0.04717,"ingestedAt":"2026-09-17T16:21:47.816Z","slug":"CVE-2026-90347","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\narm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry\n\nCommit e057b9477232 (\"arm64: syscall: Ensure saved x0 is kept in-sync\nwith tracer updates\") attempted to resolve a long-standing issue with\nsyscall entry tracing, where a tracer is able to manipulate the first\nsyscall argument without being subjected to seccomp or audit checking.\n\nUnfortunately, that fix was incomplete [1], as it failed to update\n'orig_x0' between a tracer updating x0 during a seccomp ptrace exit\n(SECCOMP_RET_TRACE) and the seccomp filter being re-evaluated.\n\nRather than add hooks to the core seccomp code, instead move the\nsynchronisation code into the ptrace GPR and syscall setting code so\nthat 'orig_x0' is kept up to date with x0 whenever we're stopped on the\nsyscall entry path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":207269,"id":"CVE-2026-90347","ts":1789757340169,"field":"cvss","old":null,"new":"8.4"},{"seq":207268,"id":"CVE-2026-90347","ts":1789757340169,"field":"severity","old":"none","new":"high"}]}