Medium severity5.5NVD Advisory· Published Jun 26, 2026· Updated Jul 8, 2026
CVE-2026-53287
CVE-2026-53287
Description
In the Linux kernel, the following vulnerability has been resolved:
audit: fix incorrect inheritable capability in CAPSET records
__audit_log_capset() records the effective capability set into the inheritable field due to a copy-paste error. Every CAPSET audit record therefore reports cap_pi (process inheritable) with the value of cap_effective instead of cap_inheritable.
This silently corrupts audit data used for compliance and forensic analysis: an attacker who modifies inheritable capabilities to prepare for a privilege-escalating exec would have the change masked in the audit trail.
The bug has been present since the original introduction of CAPSET audit records in 2008.
Affected products
19- osv-coords14 versionspkg:linux/kernelpkg:rpm/opensuse/dtb-aarch64&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-64kb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default-base&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-docs&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-kvmsmall&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-build&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-qa&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-syms&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-zfcpdump&distro=openSUSE%20Leap%2016.0
>= 2.6.29, < 5.10.258+ 13 more
- (no CPE)range: >= 2.6.29, < 5.10.258
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1.160000.2.17
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/0a065c51a225854768b772a0b733a44d77162582nvdPatch
- git.kernel.org/stable/c/151ee470edc3d7ed29fe72df678f8357d2ad8cednvdPatch
- git.kernel.org/stable/c/75bd76c9eb2de9afeca03dc5152ebca5fb8fc816nvdPatch
- git.kernel.org/stable/c/95de7bb4bf535a9288549d401ebde83cdcbf2792nvdPatch
- git.kernel.org/stable/c/d782e4d200cd9036ef353eeb29525bfbfd13a14envdPatch
- git.kernel.org/stable/c/e35f3550c5b4fab33103c18654c293cee9850b0anvdPatch
- git.kernel.org/stable/c/e4a640475e43f406fdfd56d370b1f34b0cbbc18dnvdPatch
- git.kernel.org/stable/c/febb4bf373ac565d3fb8d1f429827bdd983be496nvdPatch
News mentions
0No linked articles in our index yet.