CVE-2026-89603High· 7.0▾ TwilightA flaw was found in the Linux kernel. A race condition exists where a seccomp filter, intended to restrict system calls, can be bypassed by an unprivileged process. This occurs when a thread is stopped for tracing (ptrace) and another thre…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 7.8
none → high
— → 7.8
none → high
— → 8.4
none → high
8.4 → 7.8
7.8 → 8.4
Last analysed / modified upstream
8.4 → 7
A flaw was found in the Linux kernel. A race condition exists where a seccomp filter, intended to restrict system calls, can be bypassed by an unprivileged process. This occurs when a thread is stopped for tracing (ptrace) and another thread attempts to apply a seccomp filter with the SECCOMP_FILTER_FLAG_TSYNC flag. Due to a caching issue, the newly installed filter is not properly enforced, allowing the unprivileged process to execute system calls that should have been blocked, potentially leading to a security bypass.
kernel: entry: Fix seccomp bypass after ptrace with TSYNC — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-15.
Affected:
No fix planned:
Not affected:
Affected
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89487High· 7.0kernel: openvswitch: only skb_tx_error() a packet we are about to drop (CVE-2026-89487)
CVE-2026-89508Medium· 5.5kernel: RDMA/ucma: Lock the handler in ucma_set_ib_path() (CVE-2026-89508)
CVE-2026-80948Medium· 5.5kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() (CVE-2026-80948)
CVE-2026-80936Medium· 5.5kernel: wifi: mt76: mt7925: cancel mlo_pm_work on stop (CVE-2026-80936)
CVE-2026-80947High· 7.0kernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (CVE-2026-80947)
CVE-2026-80980Medium· 5.5kernel: net/smc: stop killed, freed and out_of_sync sharing a byte (CVE-2026-80980)