SELinux Policycoreutils 3.10 Unconfined Kill Auth Bypass
CVE-2026-59677 Published on July 23, 2026
Process Kill Attack Vector in killall() in seunshare
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in
unconfined context
This issue affects policycoreutils through 3.10.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-59677 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-59677
Want to know whenever a new CVE is published for Selinuxproject Selinux? stack.watch will email you.
Affected Versions
SELinuxProject selinux:- Before and including 3.10 is affected.