CVE-2026-90347 PUBLISHED

arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syscall entry

Commit e057b9477232 ("arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates") attempted to resolve a long-standing issue with syscall entry tracing, where a tracer is able to manipulate the first syscall argument without being subjected to seccomp or audit checking.

Unfortunately, that fix was incomplete [1], as it failed to update 'orig_x0' between a tracer updating x0 during a seccomp ptrace exit (SECCOMP_RET_TRACE) and the seccomp filter being re-evaluated.

Rather than add hooks to the core seccomp code, instead move the synchronisation code into the ptrace GPR and syscall setting code so that 'orig_x0' is kept up to date with x0 whenever we're stopped on the syscall entry path.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from a5cd110cb8369d6b37ef5ccfe56b3fa1338c9615 to f433869f23841a50455c4087d85540d5b4d37cde (excl.)
  • affected from a5cd110cb8369d6b37ef5ccfe56b3fa1338c9615 to 88b839ce497ccb1ff92f7ae742c78dd2937ba572 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.8 is affected
  • unaffected from 0 to 4.8 (excl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References