CVE-2026-53287

In the Linux kernel, the following vulnerability has been resolved: audit: fix incorrect inheritable capability in CAPSET records __audit_log_capset() records the effective capability set into the inheritable field due to a copy-paste error. Every CAPSET audit record therefore reports cap_pi (process inheritable) with the value of cap_effective instead of cap_inheritable. This silently corrupts audit data used for compliance and forensic analysis: an attacker who modifies inheritable capabilities to prepare for a privilege-escalating exec would have the change masked in the audit trail. The bug has been present since the original introduction of CAPSET audit records in 2008.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*

History

08 Jul 2026, 03:54

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/0a065c51a225854768b772a0b733a44d77162582 - () https://git.kernel.org/stable/c/0a065c51a225854768b772a0b733a44d77162582 - Patch
References () https://git.kernel.org/stable/c/151ee470edc3d7ed29fe72df678f8357d2ad8ced - () https://git.kernel.org/stable/c/151ee470edc3d7ed29fe72df678f8357d2ad8ced - Patch
References () https://git.kernel.org/stable/c/75bd76c9eb2de9afeca03dc5152ebca5fb8fc816 - () https://git.kernel.org/stable/c/75bd76c9eb2de9afeca03dc5152ebca5fb8fc816 - Patch
References () https://git.kernel.org/stable/c/95de7bb4bf535a9288549d401ebde83cdcbf2792 - () https://git.kernel.org/stable/c/95de7bb4bf535a9288549d401ebde83cdcbf2792 - Patch
References () https://git.kernel.org/stable/c/d782e4d200cd9036ef353eeb29525bfbfd13a14e - () https://git.kernel.org/stable/c/d782e4d200cd9036ef353eeb29525bfbfd13a14e - Patch
References () https://git.kernel.org/stable/c/e35f3550c5b4fab33103c18654c293cee9850b0a - () https://git.kernel.org/stable/c/e35f3550c5b4fab33103c18654c293cee9850b0a - Patch
References () https://git.kernel.org/stable/c/e4a640475e43f406fdfd56d370b1f34b0cbbc18d - () https://git.kernel.org/stable/c/e4a640475e43f406fdfd56d370b1f34b0cbbc18d - Patch
References () https://git.kernel.org/stable/c/febb4bf373ac565d3fb8d1f429827bdd983be496 - () https://git.kernel.org/stable/c/febb4bf373ac565d3fb8d1f429827bdd983be496 - Patch
First Time Linux linux Kernel
Linux

26 Jun 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 20:17

Updated : 2026-07-08 03:54


NVD link : CVE-2026-53287

Mitre link : CVE-2026-53287

CVE.ORG link : CVE-2026-53287


JSON object : View

Products Affected

linux

  • linux_kernel