CVE-2026-80663

Source
https://cve.org/CVERecord?id=CVE-2026-80663
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80663.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80663
Downstream
Published
2026-08-28T06:49:06.882Z
Modified
2026-08-31T03:30:39.456763936Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
tools/power/x86/intel-speed-select: Harden daemon pidfile open
Details

In the Linux kernel, the following vulnerability has been resolved:

tools/power/x86/intel-speed-select: Harden daemon pidfile open

Avoid symlink-based pidfile clobbering by opening the pidfile with O_NOFOLLOW and validating it with fstat() before locking/writing.

The daemon currently uses a fixed pidfile path under /tmp. A local unprivileged user can pre-create a symlink at that path and cause a root-run daemon instance to write into an attacker-chosen file.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80663.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7fd786dfbd2c55ddee3b87f33c82f1c58bdb1dd6
Fixed
905493a6338c82a70da16f86e0a6215db5a3d73d
Fixed
db938eb9a3c1317596c28e94413b33426508d51b
Fixed
72a07abc6b9046f07a08bba353cad7667bcc9dce
Fixed
19ffeb30fdfce63f8d6aca71bcdddb3f69d46278
Fixed
e8adac69d1bdf035ef97cc914e845acd4ef08e28
Fixed
607af438e6430893a822964c841a1994b33acccc

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80663.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80663.json"