CVE-2026-78408

Description

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

Statement

Affected versions: util-linux v2.40 through v2.42.2. The --join-cgroup option was introduced in v2.40; earlier releases (including util-linux 2.38) are not affected. Fixed in v2.41.6 and v2.42.3.

Mitigation

Upgrade to util-linux v2.41.6, v2.42.3, or later. Until a fix is applied, do not run nsenter --join-cgroup (including nsenter --target PID --all --join-cgroup) against untrusted processes or namespaces. The fix closes the cgroup.procs descriptor immediately after joining, and opens it with O_CLOEXEC.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.9N/A7.9
Attack VectorLocalN/ALocal
Attack ComplexityLowN/ALow
Privileges RequiredLowN/ALow
User InteractionRequiredN/ARequired
ScopeChangedN/AChanged
ConfidentialityNoneN/ANone
Integrity ImpactHighN/AHigh
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H

cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H

Red Hat CVSS v3 Score Explanation

UI:R because a privileged operator must run nsenter --join-cgroup against the attacker-controlled target. S:C because the leaked root-opened cgroup.procs FD lets an unprivileged process migrate host root tasks into attacker-owned cgroups. C:N because no confidentiality primitive was demonstrated.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (Other)

An attacker that can influence the allocation of resources that are not properly released could deplete the available resource pool and prevent all other processes from accessing the same type of resource.

Acknowledgements

Red Hat would like to thank Andreas Gabriel Berbescu (Independent Security Researcher) for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.