Description

In the Linux kernel, the following vulnerability has been resolved: audit: fix incorrect inheritable capability in CAPSET records __audit_log_capset() records the effective capability set into the inheritable field due to a copy-paste error. Every CAPSET audit record therefore reports cap_pi (process inheritable) with the value of cap_effective instead of cap_inheritable. This silently corrupts audit data used for compliance and forensic analysis: an attacker who modifies inheritable capabilities to prepare for a privilege-escalating exec would have the change masked in the audit trail. The bug has been present since the original introduction of CAPSET audit records in 2008.

Affected products

VendorProductVersions
LinuxLinuxe68b75a027bb94066576139ee33676264f867b87 to <75bd76c9eb2de9afeca03dc5152ebca5fb8fc816; e68b75a027bb94066576139ee33676264f867b87 to <febb4bf373ac565d3fb8d1f429827bdd983be496; e68b75a027bb94066576139ee33676264f867b87 to <95de7bb4bf535a9288549d401ebde83cdcbf2792; e68b75a027bb94066576139ee33676264f867b87 to <151ee470edc3d7ed29fe72df678f8357d2ad8ced; e68b75a027bb94066576139ee33676264f867b87 to <0a065c51a225854768b772a0b733a44d77162582; e68b75a027bb94066576139ee33676264f867b87 to <e35f3550c5b4fab33103c18654c293cee9850b0a; e68b75a027bb94066576139ee33676264f867b87 to <d782e4d200cd9036ef353eeb29525bfbfd13a14e; e68b75a027bb94066576139ee33676264f867b87 to <e4a640475e43f406fdfd56d370b1f34b0cbbc18d
LinuxLinux2.6.29; 0 to <2.6.29; 5.10.258 to <=5.10.*; 5.15.209 to <=5.15.*; 6.1.175 to <=6.1.*; 6.6.141 to <=6.6.*; 6.12.91 to <=6.12.*; 6.18.33 to <=6.18.*; 7.0.10 to <=7.0.*; 7.1 to <=*

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 27 Jun 2026 07:02 UTC.