5.5
MEDIUM CVSS 3.1
CVE-2026-53287
audit: fix incorrect inheritable capability in CAPSET records
Description

In the Linux kernel, the following vulnerability has been resolved: audit: fix incorrect inheritable capability in CAPSET records __audit_log_capset() records the effective capability set into the inheritable field due to a copy-paste error. Every CAPSET audit record therefore reports cap_pi (process inheritable) with the value of cap_effective instead of cap_inheritable. This silently corrupts audit data used for compliance and forensic analysis: an attacker who modifies inheritable capabilities to prepare for a privilege-escalating exec would have the change masked in the audit trail. The bug has been present since the original introduction of CAPSET audit records in 2008.

INFO

Published Date :

June 26, 2026, 8:17 p.m.

Last Modified :

July 8, 2026, 3:54 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-53287 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 MEDIUM [email protected]
Solution
Apply the Linux kernel patch to correct audit record capability logging.
  • Update the Linux kernel to the patched version.
  • Verify audit logs capture correct inheritable capabilities.
  • Review historical audit logs for discrepancies.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-53287 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-53287 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-53287 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-53287 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Jul. 08, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    Added CWE NVD-CWE-noinfo
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.141 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.91 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.33 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.10 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.175 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.209 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 2.6.29 up to (excluding) 5.10.258
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/0a065c51a225854768b772a0b733a44d77162582 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/151ee470edc3d7ed29fe72df678f8357d2ad8ced Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/75bd76c9eb2de9afeca03dc5152ebca5fb8fc816 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/95de7bb4bf535a9288549d401ebde83cdcbf2792 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/d782e4d200cd9036ef353eeb29525bfbfd13a14e Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/e35f3550c5b4fab33103c18654c293cee9850b0a Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/e4a640475e43f406fdfd56d370b1f34b0cbbc18d Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/febb4bf373ac565d3fb8d1f429827bdd983be496 Types: Patch
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 26, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'e68b75a027bb94066576139ee33676264f867b87', 'lessThan': '75bd76c9eb2de9afeca03dc5152ebca5fb8fc816', 'versionType': 'git'}, {'status': 'affected', 'version': 'e68b75a027bb94066576139ee33676264f867b87', 'lessThan': 'febb4bf373ac565d3fb8d1f429827bdd983be496', 'versionType': 'git'}, {'status': 'affected', 'version': 'e68b75a027bb94066576139ee33676264f867b87', 'lessThan': '95de7bb4bf535a9288549d401ebde83cdcbf2792', 'versionType': 'git'}, {'status': 'affected', 'version': 'e68b75a027bb94066576139ee33676264f867b87', 'lessThan': '151ee470edc3d7ed29fe72df678f8357d2ad8ced', 'versionType': 'git'}, {'status': 'affected', 'version': 'e68b75a027bb94066576139ee33676264f867b87', 'lessThan': '0a065c51a225854768b772a0b733a44d77162582', 'versionType': 'git'}, {'status': 'affected', 'version': 'e68b75a027bb94066576139ee33676264f867b87', 'lessThan': 'e35f3550c5b4fab33103c18654c293cee9850b0a', 'versionType': 'git'}, {'status': 'affected', 'version': 'e68b75a027bb94066576139ee33676264f867b87', 'lessThan': 'd782e4d200cd9036ef353eeb29525bfbfd13a14e', 'versionType': 'git'}, {'status': 'affected', 'version': 'e68b75a027bb94066576139ee33676264f867b87', 'lessThan': 'e4a640475e43f406fdfd56d370b1f34b0cbbc18d', 'versionType': 'git'}], 'programFiles': ['kernel/auditsc.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.29'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.29', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.258', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.209', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.175', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.141', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.91', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.33', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.10', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['kernel/auditsc.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: audit: fix incorrect inheritable capability in CAPSET records __audit_log_capset() records the effective capability set into the inheritable field due to a copy-paste error. Every CAPSET audit record therefore reports cap_pi (process inheritable) with the value of cap_effective instead of cap_inheritable. This silently corrupts audit data used for compliance and forensic analysis: an attacker who modifies inheritable capabilities to prepare for a privilege-escalating exec would have the change masked in the audit trail. The bug has been present since the original introduction of CAPSET audit records in 2008.
    Added Reference https://git.kernel.org/stable/c/0a065c51a225854768b772a0b733a44d77162582
    Added Reference https://git.kernel.org/stable/c/151ee470edc3d7ed29fe72df678f8357d2ad8ced
    Added Reference https://git.kernel.org/stable/c/75bd76c9eb2de9afeca03dc5152ebca5fb8fc816
    Added Reference https://git.kernel.org/stable/c/95de7bb4bf535a9288549d401ebde83cdcbf2792
    Added Reference https://git.kernel.org/stable/c/d782e4d200cd9036ef353eeb29525bfbfd13a14e
    Added Reference https://git.kernel.org/stable/c/e35f3550c5b4fab33103c18654c293cee9850b0a
    Added Reference https://git.kernel.org/stable/c/e4a640475e43f406fdfd56d370b1f34b0cbbc18d
    Added Reference https://git.kernel.org/stable/c/febb4bf373ac565d3fb8d1f429827bdd983be496
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.