CVE-2026-23241: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at" variant of getxattr() and listxattr() are missing from the audit read class. Calling getxattrat() or listxattrat() on a file to read its extended attributes will bypass audit rules such as: -w /tmp/test -p rwa -k test_rwa The current patch adds missing syscalls to the audit read class.
Affected products
- Linux Linux Kernel: from 6.13, before 6.18.16 (fixed in 6.18.16); from 6.19, before 6.19.6 (fixed in 6.19.6)
Published 2026-03-17. Last modified 2026-06-17.