{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68186","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.373Z","datePublished":"2026-08-10T11:59:58.299Z","dateUpdated":"2026-08-19T16:30:54.269Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:30:54.269Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: set have_execfd only once the interpreter is opened\n\nload_misc_binary() raises bprm->have_execfd as soon as it sees the 'O'\n(or 'C') flag. This happens well before it opens the interpreter. If\nthat open fails the flag stays set on the bprm. binfmt_misc is at the\nhead of the format list so an interpreter open failure that returns\n-ENOEXEC lets the search fall through to a later format. This means it\nruns the matched binary directly having never staged an interpreter. So\nbprm->executable is NULL while have_execfd falsely claims a descriptor\nis present.\n\nConsequently, begin_new_exec() dereferences the missing executable:\n\n  would_dump(bprm, bprm->executable);\n\nand NULL derefs. Had it not, the hand-off later in the same function\nwould have failed anyway. FD_ADD(0, bprm->executable) rejects a NULL\nfile with -ENOMEM. Both sites are past the point of no return so the\nexec cannot be unwound either way.\n\nThis can be reached by unprivileged users as binfmt_misc can be mounted\nin user namespaces. So a user can register an 'O' entry whose\ninterpreter lives on a FUSE mount, have the FUSE server fail the open\nwith -ENOEXEC and execute a native ELF file that matches the entry.\n\nhave_execfd only means anything alongside the executable it describes\nwhich is not set until the interpreter has been opened and staged.\nSo lets raise it there, next to execfd_creds, which is already set at\nthat point. An open failure now leaves it clear, so the fallback format\nderives credentials from the binary and emits no AT_EXECFD, as it would\nfor any native exec. The argv rewrite load_misc_binary() performs before\nthe open is still not undone. This means the binary sees the interpreter\npath in argv[0] and its own path in argv[1] but that predates this\nchange and only became observable once the exec stopped faulting."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/binfmt_misc.c"],"versions":[{"version":"bc2bf338d54b7aadaed49bb45b9e10d4592b2a46","lessThan":"a8e9e9450df44e9dd529ec5beff283f48f4f4b97","status":"affected","versionType":"git"},{"version":"bc2bf338d54b7aadaed49bb45b9e10d4592b2a46","lessThan":"a261dc49d99681c9c71f38d16e31812dc3e30412","status":"affected","versionType":"git"},{"version":"bc2bf338d54b7aadaed49bb45b9e10d4592b2a46","lessThan":"40c09b7a1d4e0a4866042c87c2bd911bb57566c8","status":"affected","versionType":"git"},{"version":"bc2bf338d54b7aadaed49bb45b9e10d4592b2a46","lessThan":"0f19d54e2524f0bf183b82f365ae4e49b4a2f788","status":"affected","versionType":"git"},{"version":"bc2bf338d54b7aadaed49bb45b9e10d4592b2a46","lessThan":"2dd0298905e97795a9c5ec30cf5b41975f821632","status":"affected","versionType":"git"},{"version":"bc2bf338d54b7aadaed49bb45b9e10d4592b2a46","lessThan":"1cd4e9b7967dab48c9f79a00b06ffff7208c0993","status":"affected","versionType":"git"},{"version":"bc2bf338d54b7aadaed49bb45b9e10d4592b2a46","lessThan":"5ccc99d58f94fad258c9c375715b3974e48620e8","status":"affected","versionType":"git"},{"version":"bc2bf338d54b7aadaed49bb45b9e10d4592b2a46","lessThan":"bbf5f639918dc011aaf60aab8480218758ee68c5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/binfmt_misc.c"],"versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a8e9e9450df44e9dd529ec5beff283f48f4f4b97"},{"url":"https://git.kernel.org/stable/c/a261dc49d99681c9c71f38d16e31812dc3e30412"},{"url":"https://git.kernel.org/stable/c/40c09b7a1d4e0a4866042c87c2bd911bb57566c8"},{"url":"https://git.kernel.org/stable/c/0f19d54e2524f0bf183b82f365ae4e49b4a2f788"},{"url":"https://git.kernel.org/stable/c/2dd0298905e97795a9c5ec30cf5b41975f821632"},{"url":"https://git.kernel.org/stable/c/1cd4e9b7967dab48c9f79a00b06ffff7208c0993"},{"url":"https://git.kernel.org/stable/c/5ccc99d58f94fad258c9c375715b3974e48620e8"},{"url":"https://git.kernel.org/stable/c/bbf5f639918dc011aaf60aab8480218758ee68c5"}],"title":"binfmt_misc: set have_execfd only once the interpreter is opened","x_generator":{"engine":"bippy-1.2.0"}}}}