Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks for ns iteration ioctls Even privileged services should not necessarily be able to see other privileged service’s namespaces so they can’t leak information to each other. Use may_see_all_namespaces() helper that centralizes this policy until the nstree adapts. A flaw was found in the Linux kernel’snsfs component. This vulnerability allows privileged services to bypass permission checks related to namespace iteration input/output controls (ioctls). As a result, one privileged service could potentially view information from other privileged services, leading to unauthorized information disclosure.
Details
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Debian 13 | Planned | — |