Red HatCVE-2026-78408
The nsenter --join-cgroup option opens the target cgroup.procs file as root and...
High7.9CVE-2026-78408 · Published Sep 2, 2026 · updated Sep 5, 2026
The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-775
- www.cve.org/CVERecord?id=CVE-2026-78408
- nvd.nist.gov/vuln/detail/CVE-2026-78408
- access.redhat.com/errata/RHSA-2026:63162
- access.redhat.com/security/cve/CVE-2026-78408
- bugzilla.redhat.com/show_bug.cgi?id=2522497
- github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj
- www.openwall.com/lists/oss-security/2026/09/05/2
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | Red Hat Advanced Cluster Management for Kubernetes 2: remote code execution | Critical9.1 | No fix yet |
| Sep 2 | Red Hat rpm: command injection | High7.8 | No fix yet |
| Sep 2 | Red Hat Enterprise Linux 10: command injection | High7.8 | No fix yet |
| Sep 2 | Red Hat Enterprise Linux 10: link following | High7.0 | No fix yet |
| Sep 2 | Red Hat util-linux: race condition | High7.8 | No fix yet |
| Sep 2 | Red Hat Enterprise Linux: open redirect | Medium4.3 | No fix yet |