SELinux Policycoreutils 3.10 Unconfined Kill Auth Bypass
CVE-2026-59677 Published on July 23, 2026

Process Kill Attack Vector in killall() in seunshare
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.

NVD

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-59677 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-59677

Want to know whenever a new CVE is published for Selinuxproject Selinux? stack.watch will email you.

 

Affected Versions

SELinuxProject selinux: