Description
In the Linux kernel, the following vulnerability has been resolved: audit: fix incorrect inheritable capability in CAPSET records __audit_log_capset() records the effective capability set into the inheritable field due to a copy-paste error. Every CAPSET audit record therefore reports cap_pi (process inheritable) with the value of cap_effective instead of cap_inheritable. This silently corrupts audit data used for compliance and forensic analysis: an attacker who modifies inheritable capabilities to prepare for a privilege-escalating exec would have the change masked in the audit trail. The bug has been present since the original introduction of CAPSET audit records in 2008.
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | e68b75a027bb94066576139ee33676264f867b87 to <75bd76c9eb2de9afeca03dc5152ebca5fb8fc816; e68b75a027bb94066576139ee33676264f867b87 to <febb4bf373ac565d3fb8d1f429827bdd983be496; e68b75a027bb94066576139ee33676264f867b87 to <95de7bb4bf535a9288549d401ebde83cdcbf2792; e68b75a027bb94066576139ee33676264f867b87 to <151ee470edc3d7ed29fe72df678f8357d2ad8ced; e68b75a027bb94066576139ee33676264f867b87 to <0a065c51a225854768b772a0b733a44d77162582; e68b75a027bb94066576139ee33676264f867b87 to <e35f3550c5b4fab33103c18654c293cee9850b0a; e68b75a027bb94066576139ee33676264f867b87 to <d782e4d200cd9036ef353eeb29525bfbfd13a14e; e68b75a027bb94066576139ee33676264f867b87 to <e4a640475e43f406fdfd56d370b1f34b0cbbc18d |
| Linux | Linux | 2.6.29; 0 to <2.6.29; 5.10.258 to <=5.10.*; 5.15.209 to <=5.15.*; 6.1.175 to <=6.1.*; 6.6.141 to <=6.6.*; 6.12.91 to <=6.12.*; 6.18.33 to <=6.18.*; 7.0.10 to <=7.0.*; 7.1 to <=* |
References
- https://git.kernel.org/stable/c/75bd76c9eb2de9afeca03dc5152ebca5fb8fc816
- https://git.kernel.org/stable/c/febb4bf373ac565d3fb8d1f429827bdd983be496
- https://git.kernel.org/stable/c/95de7bb4bf535a9288549d401ebde83cdcbf2792
- https://git.kernel.org/stable/c/151ee470edc3d7ed29fe72df678f8357d2ad8ced
- https://git.kernel.org/stable/c/0a065c51a225854768b772a0b733a44d77162582
- https://git.kernel.org/stable/c/e35f3550c5b4fab33103c18654c293cee9850b0a
- https://git.kernel.org/stable/c/d782e4d200cd9036ef353eeb29525bfbfd13a14e
- https://git.kernel.org/stable/c/e4a640475e43f406fdfd56d370b1f34b0cbbc18d
Generated from the official CVE List on 27 Jun 2026 07:02 UTC.