CVE-2026-58089CWE-273

CVE-2026-58089

High · published August 26, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
2.0
In the wild
Unconfirmed
What it is

When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly.

An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process executes a setuid or setgid binary, contrary to the intended policy.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00119 · 2.0th percentile
Weakness
CWE-273 · Improper Check for Dropped Privileges
Published
2026-08-26T09:18Z
References (1)
EPSS history
Timeline
  • 27 AUG 06:37Z
    EPSS moved — → 0%
    epss
  • 26 AUG 04:30Z
    hwpmc fails to detach PMCs during exec credential transitions
    cvelistv5