VYPR
Medium severity5.5NVD Advisory· Published Mar 17, 2026· Updated Jun 17, 2026

CVE-2026-23241

CVE-2026-23241

Description

In the Linux kernel, the following vulnerability has been resolved:

audit: add missing syscalls to read class

The "at" variant of getxattr() and listxattr() are missing from the audit read class. Calling getxattrat() or listxattrat() on a file to read its extended attributes will bypass audit rules such as:

-w /tmp/test -p rwa -k test_rwa

The current patch adds missing syscalls to the audit read class.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.13,<6.18.16
    • (no CPE)range: 6.13
    • (no CPE)
  • osv-coords
    Range: >= 6.13.0, < 6.18.16

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.