CVE-2026-43403 (GCVE-0-2026-43403)
Vulnerability from cvelistv5
Published
2026-05-08 14:21
Modified
2026-08-05 12:27
Summary
In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks for ns iteration ioctls Even privileged services should not necessarily be able to see other privileged service's namespaces so they can't leak information to each other. Use may_see_all_namespaces() helper that centralizes this policy until the nstree adapts.
Impacted products
Vendor Product Version
Linux Linux Version: a1d220d9dafa8d76ba60a784a1016c3134e6a1e8
Version: a1d220d9dafa8d76ba60a784a1016c3134e6a1e8
Version: a1d220d9dafa8d76ba60a784a1016c3134e6a1e8
Version: a1d220d9dafa8d76ba60a784a1016c3134e6a1e8
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/nsfs.c",
            "include/linux/ns_common.h",
            "kernel/nscommon.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "3376b345df155ca36d8611857b41ff7d5183fc38",
              "status": "affected",
              "version": "a1d220d9dafa8d76ba60a784a1016c3134e6a1e8",
              "versionType": "git"
            },
            {
              "lessThan": "2f3dea284c761c890d676f77d5e55c0c496b4ef4",
              "status": "affected",
              "version": "a1d220d9dafa8d76ba60a784a1016c3134e6a1e8",
              "versionType": "git"
            },
            {
              "lessThan": "0ad650e60150eda789deca5e78a6a09d26bf8fc9",
              "status": "affected",
              "version": "a1d220d9dafa8d76ba60a784a1016c3134e6a1e8",
              "versionType": "git"
            },
            {
              "lessThan": "e6b899f08066e744f89df16ceb782e06868bd148",
              "status": "affected",
              "version": "a1d220d9dafa8d76ba60a784a1016c3134e6a1e8",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/nsfs.c",
            "include/linux/ns_common.h",
            "kernel/nscommon.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "lessThan": "6.12",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.78",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.20",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.9",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.78",
                  "versionStartIncluding": "6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.20",
                  "versionStartIncluding": "6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.9",
                  "versionStartIncluding": "6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "6.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnsfs: tighten permission checks for ns iteration ioctls\n\nEven privileged services should not necessarily be able to see other\nprivileged service\u0027s namespaces so they can\u0027t leak information to each\nother. Use may_see_all_namespaces() helper that centralizes this policy\nuntil the nstree adapts."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable path is reached by a local `ioctl()` on an nsfs mount-namespace file descriptor, such as one obtained from `/proc/self/ns/mnt` or pidfd namespace ioctls. There is no network, adjacent, or physical attack path.\nAC:L - Triggering is deterministic: open a mount namespace fd and issue `NS_MNT_GET_NEXT` or `NS_MNT_GET_PREV`. There is no race or special memory-layout condition required.\nPR:L - The pre-fix check only required `CAP_SYS_ADMIN` in the target mount namespace\u0027s owning user namespace, which can be satisfied through user namespaces in plausible deployments. Under the higher-severity rule, this is Low rather than High.\nUI:N - No victim interaction is needed once the attacker has local execution and the relevant namespace capability. The attacker directly invokes the ioctl.\nS:C - The bug lets one namespace-confined service obtain file descriptors for other mount namespaces, bypassing the intended namespace visibility boundary. That can cross container or service isolation boundaries.\nC:H - The returned namespace fd and mount namespace id allow enumeration with `listmount()` and `statmount()`, exposing mount topology, paths, sources, options, and related metadata from another namespace. In plausible privileged-container scenarios, the fd can also enable `setns()` into the target mount namespace and expose sensitive filesystem contents.\nI:H - With the leaked mount namespace fd and the same namespace capabilities required by the vulnerable path, an attacker can plausibly `setns()` into another mount namespace and modify writable files or mount state there. This can compromise integrity across the namespace boundary.\nA:H - After obtaining and entering another mount namespace in a privileged scenario, the attacker can disrupt that namespace by altering or unmounting resources or damaging writable files. This can cause high availability impact to the affected service or container."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:27:47.212Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3376b345df155ca36d8611857b41ff7d5183fc38"
        },
        {
          "url": "https://git.kernel.org/stable/c/2f3dea284c761c890d676f77d5e55c0c496b4ef4"
        },
        {
          "url": "https://git.kernel.org/stable/c/0ad650e60150eda789deca5e78a6a09d26bf8fc9"
        },
        {
          "url": "https://git.kernel.org/stable/c/e6b899f08066e744f89df16ceb782e06868bd148"
        }
      ],
      "title": "nsfs: tighten permission checks for ns iteration ioctls",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-43403",
    "datePublished": "2026-05-08T14:21:44.204Z",
    "dateReserved": "2026-05-01T14:12:56.007Z",
    "dateUpdated": "2026-08-05T12:27:47.212Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…