Back to overview

CVE-2026-53287

Description
In the Linux kernel, the following vulnerability has been resolved: audit: fix incorrect inheritable capability in CAPSET records __audit_log_capset() records the effective capability set into the inheritable field due to a copy-paste error. Every CAPSET audit record therefore reports cap_pi (process inheritable) with the value of cap_effective instead of cap_inheritable. This silently corrupts audit data used for compliance and forensic analysis: an attacker who modifies inheritable capabilities to prepare for a privilege-escalating exec would have the change masked in the audit trail. The bug has been present since the original introduction of CAPSET audit records in 2008.

Metadata

CVE ID
CVE-2026-53287
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-26 19:40 UTC
Last updated
2026-06-26 19:40 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux e68b75a027bb94066576139ee33676264f867b87 < 75bd76c9eb2de9afeca03dc5152ebca5fb8fc816, e68b75a027bb94066576139ee33676264f867b87 < febb4bf373ac565d3fb8d1f429827bdd983be496, e68b75a027bb94066576139ee33676264f867b87 < 95de7bb4bf535a9288549d401ebde83cdcbf2792, e68b75a027bb94066576139ee33676264f867b87 < 151ee470edc3d7ed29fe72df678f8357d2ad8ced …
Linux Linux 2.6.29, 0 < 2.6.29, 5.10.258 ≤ 5.10.*, 5.15.209 ≤ 5.15.* …
Back to overview