CVE-2026-78408
The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.9
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
- EPSS probability
- 0.11%
- CWE
- CWE-775
- Published
- 2026-09-02
- Last modified
- 2026-09-05
Affected products
- Red Hat Red Hat Hardened Images
Weakness type
Related vulnerabilities
- CVE-2026-45287 — OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse
- CVE-2019-25557 — TwistedBrush Pro Studio 24.06 Denial of Service via srp File
- CVE-2025-13751 — Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on...
- CVE-2025-53476 — A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3...
- CVE-2017-8452 — Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be...