What is CVE-2026-72693?
CVE-2026-72693 affects `openvt -u`, where the `stat()` call on `/proc/<pid>/fd/0` follows symlinks, potentially allowing privilege escalation. Users relying on the `kbrequest`/init configuration should immediately apply updates or temporarily disable usage of `openvt -u`.
Azərbaycanca: CVE-2026-72693 `openvt -u` əmrində aşkarlanıb, burada `/proc/<pid>/fd/0` üzərində `stat()` çağırışı simlink izləyir, bu da hüquq yüksəltməyə imkan verə bilər. Təsirə məruz qalan sistemlərdə `kbrequest`/init konfiqurasiyası istifadə edən istifadəçilər təcili olaraq yeniləmə tətbiq etməli və ya müvəqqəti olaraq `openvt -u` istifadəsini dayandırmalıdır.
FAQ2
Which component does CVE-2026-72693 affect and what is the root cause?
The vulnerability affects the `openvt -u` command. The root cause is that the `stat()` call on `/proc/<pid>/fd/0` follows symlinks.
What temporary mitigation is recommended for CVE-2026-72693?
Until an update is applied, usage of `openvt -u` should be temporarily disabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.