Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-3856: Linux core may let attackers gain system control

CVE-2026-3856 · published 1 day ago
Summary

The Linux core in Ubuntu 22.04 contains a security weakness that could allow a malicious user to run code with full system privileges. This could let an attacker take control of the server or access sensitive data. Apply the latest Linux package updates from Ubuntu or use the patch released by Root to fix the issue.

What to do
  • Update linux to version 5.15.0-198.208.aikido.116.
  • Update rootio-linux to version 5.15.0-198.208.aikido.116.
Affected software
Ecosystem VendorProductAffected versions
– ibm db2_recovery_expert 5.5.0
cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:linux:*:*
Root:Ubuntu:22.04 – linux < 5.15.0-198.208.aikido.116
Fix: upgrade to 5.15.0-198.208.aikido.116
Root:Ubuntu:22.04 – rootio-linux < 5.15.0-198.208.aikido.116
Fix: upgrade to 5.15.0-198.208.aikido.116
Original advisory text
CVE-2026-3856 in linux - Patched by Root
Root has patched CVE-2026-3856 in the linux package for Root:Ubuntu:22.04. Multiple fixed versions available.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-353Missing Support for Integrity Check
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen18 Mar 2026
Track software like this
Free during beta