Back

MEDIUM

binfmt_misc: restore write access before closing files opened by open_exec()

Published Dec 16, 2025

Description

bm_register_write() opens an executable file using open_exec(), which internally calls do_open_execat() and denies write access on the file to avoid modification while it is being executed.

However, when an error occurs, bm_register_write() closes the file using filp_close() directly. This does not restore the write permission, which may cause subsequent write operations on the same file to fail.

Fix this by calling exe_file_allow_write_access() before filp_close() to restore the write permission properly.

Affected products

Remediation

Red Hat statement

This bug affects file permission state handling rather than security boundaries. The impact is limited to denial of write access on specific files after binfmt_misc registration errors, which is a reliability issue rather than a security vulnerability.

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Dec 16, 2025
Updated Jun 1, 2026
Reserved Dec 16, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 16, 2025
ENISA EUVD
Assigner Linux
Published Dec 16, 2025
Updated Jun 1, 2026
Exploited since n/a
EUVD-2025-203657