-

CVE-2026-80755

Medienbericht

selinux: reject a permission value exceeding the class permission count

In the Linux kernel, the following vulnerability has been resolved:

selinux: reject a permission value exceeding the class permission count

perm_read() bounds a permission value by SEL_VEC_MAX but never by the
nprim of the owning class or common, which is taken verbatim from the
policy image.  security_get_permissions() then writes perms[value - 1]
into an nprim-sized kcalloc() array, so a class declaring fewer
permissions than its largest permission value drives an out-of-bounds
heap write.  The top-level symbol tables are validated this way; the
nested per-class permission table is not.

Reject a permission whose value exceeds nprim, which is already set when
perm_read() runs.  Well-formed policies are unaffected.

[PM: tweak comment for line length]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < 6c2ab7c4549f4f2305848df834e784651dbf1676
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < dfc59a062c386d3d4415ecdab781065a645f33cc
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < a7f3d4f22d920dc3c7d75f02ece0f7bf2c58437e
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < d14b5d0e97fccd27974fedc03b903408872907fd
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.23
Status affected
Version 0
Version < 2.6.23
Status unaffected
Version <= 6.12.*
Version 6.12.108
Status unaffected
Version <= 6.18.*
Version 6.18.49
Status unaffected
Version <= 7.1.*
Version 7.1.13
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.098
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/6c2ab7c4549f4f2305848df834e784651dbf1676
https://git.kernel.org/stable/c/dfc59a062c386d3d4415ecdab781065a645f33cc
https://git.kernel.org/stable/c/a7f3d4f22d920dc3c7d75f02ece0f7bf2c58437e
https://git.kernel.org/stable/c/d14b5d0e97fccd27974fedc03b903408872907fd