CVE Database
/

CVE-2026-43403

Back to search

CVE-2026-43403

Published: May 8, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks for ns iteration ioctls Even privileged services should not necessarily be able to see other privileged service's namespaces so they can't leak information to each other. Use may_see_all_namespaces() helper that centralizes this policy until the nstree adapts.

VendorProductVersions

Linux

Linux

affected
a1d220d9dafa8d76ba60a784a1016c3134e6a1e8 - < 3376b345df155ca36d8611857b41ff7d5183fc38
affected
a1d220d9dafa8d76ba60a784a1016c3134e6a1e8 - < 2f3dea284c761c890d676f77d5e55c0c496b4ef4
affected
a1d220d9dafa8d76ba60a784a1016c3134e6a1e8 - < 0ad650e60150eda789deca5e78a6a09d26bf8fc9
affected
a1d220d9dafa8d76ba60a784a1016c3134e6a1e8 - < e6b899f08066e744f89df16ceb782e06868bd148

Linux

Linux

affected
6.12
unaffected
0 - < 6.12
unaffected
6.12.78 - <= 6.12.*
unaffected
6.18.20 - <= 6.18.*
unaffected
6.19.9 - <= 6.19.*

+1 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now