CVE-2026-80929

Executive Summary

In CVE‑2026‑80929, the Linux kernel exposed the global sysctl 'cad_pid' to non‑root users via pid/user namespace unshare, allowing unauthorized modification of reboot‑related settings. The patch relocates 'cad_pid' to kern_reboot_table[], restricting access to GLOBAL_ROOT_UID and eliminating the privilege‑escalation vector.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2026-09-11T20:18:56.647 - Last Modified: 2026-09-13T07:17:00.663

Original Description: In the Linux kernel, the following vulnerability has been resolved:

sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]

cad_pid is global, and kill_cad_pid() is only used in the root namespace.

However, due to pid_table_root_permissions(), a non-root user can unshare pid/user namespaces and modify it from the child namespace. This makes no sense and is simply wrong.

Move it to kern_reboot_table[] where it logically belongs; this ensures that only GLOBAL_ROOT_UID can read/modify this sysctl.

Note that this patch doesn't preserve "#ifdef CONFIG_PROC_SYSCTL" around the "cad_pid"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always set when kern_reboot_table[] is compiled.

"I believe that every person is born with talent."

— Maya Angelou
Source: NVD