Privilege Escalation Vulnerability in Util-Linux Software by Red Hat
CVE-2026-78408
7.9HIGH
What is CVE-2026-78408?
The vulnerability in Util-Linux arises from the nsenter --join-cgroup option, which improperly manages the opening of the target cgroup.procs file as root. This flaw creates a security risk as it allows an attacker-controlled target to inherit permissions from the original open, leading to unauthorized process manipulation. Consequently, an unprivileged user can leverage this weakness to migrate and terminate unrelated root processes, posing a significant threat to system integrity.
References
CVSS V3.1
Score:
7.9
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Andreas Gabriel Berbescu (Independent Security Researcher) for reporting this issue.