In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write()… (CVE-2026-64111)
In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write() already does before calling the LSM hook. This only matters for SELinux and AppArmor which check whether the process is being ptraced and if so, whether to allow the transition.
AI Analysis
Technical Summary
The Linux kernel contained a vulnerability in the LSM subsystem where the function lsm_set_self_attr() did not hold the cred_guard_mutex lock, unlike proc_pid_attr_write() which does. This mutex is important for SELinux and AppArmor security modules to correctly verify if a process is being ptraced before allowing security attribute transitions. The fix involves holding the cred_guard_mutex in lsm_set_self_attr() to prevent potential race conditions or incorrect security checks.
Potential Impact
The vulnerability could have allowed SELinux or AppArmor to incorrectly assess ptrace status of a process, potentially leading to unauthorized security attribute transitions. However, no known exploits in the wild have been reported. The impact is limited to systems using SELinux or AppArmor with ptrace checks in place.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to hold the cred_guard_mutex in lsm_set_self_attr(), aligning with the existing behavior in proc_pid_attr_write(). Users should apply the official Linux kernel updates that include this fix. Since no patch links or vendor advisories are provided here, users should consult their Linux distribution vendors for updated kernel packages containing this fix.
In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write()… (CVE-2026-64111)
Description
In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write() already does before calling the LSM hook. This only matters for SELinux and AppArmor which check whether the process is being ptraced and if so, whether to allow the transition.
CVSS v3.1
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel contained a vulnerability in the LSM subsystem where the function lsm_set_self_attr() did not hold the cred_guard_mutex lock, unlike proc_pid_attr_write() which does. This mutex is important for SELinux and AppArmor security modules to correctly verify if a process is being ptraced before allowing security attribute transitions. The fix involves holding the cred_guard_mutex in lsm_set_self_attr() to prevent potential race conditions or incorrect security checks.
Potential Impact
The vulnerability could have allowed SELinux or AppArmor to incorrectly assess ptrace status of a process, potentially leading to unauthorized security attribute transitions. However, no known exploits in the wild have been reported. The impact is limited to systems using SELinux or AppArmor with ptrace checks in place.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to hold the cred_guard_mutex in lsm_set_self_attr(), aligning with the existing behavior in proc_pid_attr_write(). Users should apply the official Linux kernel updates that include this fix. Since no patch links or vendor advisories are provided here, users should consult their Linux distribution vendors for updated kernel packages containing this fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-rf37-4wvf-8h47
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64111"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27a82a4a8d598912b24b
Added to database: 07/19/2026, 19:38:16 UTC
Last enriched: 07/19/2026, 19:47:06 UTC
Last updated: 07/20/2026, 19:41:21 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.