Back

HIGH

Local privilege escalation via execve(2) TOCTOU race

Published Aug 19, 2026

Description

During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. During this window, a process running as the same user can access the target process's memory via procfs or linprocfs, because the kernel's debugging permission check still saw the original credentials.

An unprivileged local user can exploit this race to modify the address space of a SUID binary before its credentials are elevated, potentially gaining full control of the affected system.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner freebsd
Published Aug 19, 2026
Updated Aug 20, 2026
Reserved May 29, 2026

CISA Vulnrichment

Updated Aug 20, 2026

NVD

Status Analyzed
Modified Sep 1, 2026

Red Hat

No data

ENISA EUVD

Assigner freebsd
Published Aug 19, 2026
Updated Aug 20, 2026

GitHub

No data