# CVE-2026-80928

## Summary

- **CVE ID:** CVE-2026-80928
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

smack: fix cred UAF in smack_file_send_sigiotask()

When inspecting the credentials of another task, objective credentials
(->real_cred, accessed with __task_cred()) must always be used.

Accessing ->cred on a non-current task is forbidden unless that task is
being created or destroyed; a task is allowed to change its own ->cred
pointer with no synchronization, and changing ->cred should only affect the
current syscall.

smack_file_send_sigiotask() was accessing both sets of credentials: First
tsk->cred, then __task_cred(tsk).

Fix it, always access the objective credentials here.

I have tested that this bug can lead to a KASAN-reported UAF of struct cred
in smack_file_send_sigiotask(), and that this fix prevents the race.

## Affected Products

- Linux — Linux (1da177e4c3f41524e886b7f1b8a0c1fc7321cac2)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (3b11a1decef07c19443d24ae926982bc8ec9f4c0)
- Linux — Linux (2.6.29)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/b5bcf3adfa27279da4401ab8f1e1a706601a92be)
- [CNA](https://git.kernel.org/stable/c/ed64aa505875a3b4defd504ee8e59e1949246a62)
- [CNA](https://git.kernel.org/stable/c/b791401bf389a1546a830d2b381ca60fe94c7870)
- [CNA](https://git.kernel.org/stable/c/fedc88e38ce979a720cd2de042578cb5df3dc8de)
- [CNA](https://git.kernel.org/stable/c/a512366d84e134a9eefc2cc40eeb6e80e2ec162c)
- [CNA](https://git.kernel.org/stable/c/7c7fe043f3099d0d35002b248967f75e55345b93)
- [CNA](https://git.kernel.org/stable/c/f9c7b1f2b9d8f4176d2632743f51400855978ace)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._