PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80663 Linux CVE debrief

The Linux kernel has a vulnerability in the intel-speed-select tool that allows a local unprivileged user to clobber a pidfile and write to an attacker-chosen file. The CVE record was published on 2026-08-28T08:16:51.503Z and has not been modified since then. This vulnerability has been resolved by hardening the daemon pidfile open with O_NOFOLLOW and validating it with fstat() before locking/writing. System administrators and users of Linux systems with the intel-speed-select tool installed should be aware of this vulnerability and take steps to mitigate it, including verifying and applying vendor-provided patches or updates, restricting access to the intel-speed-select tool, and monitoring system logs for suspicious activity. The vulnerability has a high CVSS score of 7.1 and is considered a high priority due to the local attack vector and potential for privilege escalation.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-28
Original CVE updated
2026-08-29
Advisory published
2026-08-28
Advisory updated
2026-08-29

Who should care

System administrators and users of Linux systems with the intel-speed-select tool installed should be aware of this vulnerability and take steps to mitigate it. This includes verifying and applying vendor-provided patches or updates, restricting access to the intel-speed-select tool, and monitoring system logs for suspicious activity. The vulnerability has a high CVSS score of 7.1 and is considered a high priority due to the local attack vector and potential for privilege escalation. The CVE record was published on 2026-08-28T08:16:51.503Z and has not been modified since then. The intel-speed-select tool is used in Linux systems and the vulnerability allows a local unprivileged user to clobber a pidfile and write to an attacker-chosen file. The vulnerability has been resolved by hardening the daemon pidfile open with O_NOFOLLOW and validating it with fstat() before locking/writing. The NVD provides official details on the vulnerability, including its CVSS score and severity. The CVE Program also provides official records of the vulnerability. Further verification is needed to determine the full scope of affected systems and potential mitigations. The vulnerability is considered a high priority due to the local attack vector and potential for privilege escalation. The Linux kernel has been updated to resolve the vulnerability. The CVE record has not been modified since its publication on 2026-08-28T08:16:51.503Z. The NVD and CVE Program provide official information on the vulnerability. The vulnerability allows a local unprivileged user to clobber a pidfile and write to an attacker-chosen file. The intel-speed-select tool is affected by the vulnerability. The vulnerability has been resolved by hardening the daemon pidfile open. System administrators and users of Linux systems with the intel-speed-select tool installed should take steps to mitigate the vulnerability. This includes verifying and applying vendor-provided patches or updates, restricting access to the intel-speed-select tool, and monitoring system logs for suspicious activity. The vulnerability is considered a high priority due to the local attack vector and potential for privilege escalation. The CVE

Technical summary

The intel-speed-select tool in the Linux kernel has a vulnerability that allows a local unprivileged user to clobber a pidfile and write to an attacker-chosen file. This is achieved by opening the pidfile with O_NOFOLLOW and validating it with fstat() before locking/writing. The vulnerability has been resolved by hardening the daemon pidfile open. The CVE record was published on 2026-08-28T08:16:51.503Z and has not been modified since then.

Defensive priority

High priority due to local attack vector and potential for privilege escalation.

Recommended defensive actions

  • Verify and apply vendor-provided patches or updates
  • Restrict access to the intel-speed-select tool
  • Monitor system logs for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The evidence for this CVE is limited, but the CVE Program and NVD provide official records of the vulnerability. Further verification is needed to determine the full scope of affected systems and potential mitigations. The intel-speed-select tool in the Linux kernel has a vulnerability that allows a local unprivileged user to clobber a pidfile and write to an attacker-chosen file. This vulnerability has been resolved by hardening the daemon pidfile open with O_NOFOLLOW and validating it with fstat() before locking/writing. System administrators and users of Linux systems with the intel-speed-select tool installed should be aware of this vulnerability and take steps to mitigate it.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80663 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80663

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80663 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80663

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/19ffeb30fdfce63f8d6aca71bcdddb3f69d46278

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/607af438e6430893a822964c841a1994b33acccc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/72a07abc6b9046f07a08bba353cad7667bcc9dce

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/905493a6338c82a70da16f86e0a6215db5a3d73d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/db938eb9a3c1317596c28e94413b33426508d51b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e8adac69d1bdf035ef97cc914e845acd4ef08e28

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.