What is CVE-2026-59677?
CVE-2026-59677 is a missing authorization vulnerability in the seunshares utility of SELinux's policycoreutils package. It allows a local user running in an unconfined context to kill root-owned processes also in an unconfined context. This issue affects policycoreutils through version 3.10, requiring an immediate patch update.
Azərbaycanca: CVE-2026-59677 SELinux policycoreutils paketindəki seunshares utilitində aşkar edilmiş çatışmayan avtorizasiya zəifliyidir. Bu, məhdudlaşdırılmamış (unconfined) kontekstdə işləyən lokal istifadəçiyə eyni kontekstdəki root-a məxsus prosesləri öldürməyə imkan verir. 3.10 versiyasına qədər təsir edir və dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which component was CVE-2026-59677 discovered?
The vulnerability was discovered in the seunshares utility of the SELinux policycoreutils package.
What can a local user do by exploiting CVE-2026-59677?
A local user running in an unconfined context can kill root-owned processes in the same unconfined context.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.