-

CVE-2026-80757

Medienbericht

selinux: reject a class permission count below its inherited common

In the Linux kernel, the following vulnerability has been resolved:

selinux: reject a class permission count below its inherited common

security_get_permissions() maps an inherited common's permissions into
an array sized by the class's own permissions.nprim, but class_read()
takes that nprim verbatim from the policy image and never checks that it
covers the common.  A class that inherits a common of N permissions while
declaring a smaller nprim is accepted, and on load the common's
permissions are written past the class-sized array -- an out-of-bounds
heap write.

Reject a class whose permission count is below its inherited common's.
Well-formed policies, where the class count already includes the
inherited permissions, are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < 2002ff745db64ac83ee1bb9ff78196d2d68bfdb3
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < 38d91446630a20ce8c2a981810deea81fd61a3b5
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < 638213f2e6ea52c06a25861616781338d154db35
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < 2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < a63011c009ea79439b800a05602b880eb4adbb05
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < acd5b09be98fd38b7392307880156fb0452a7276
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < 1b995966c3ae5244751bdaee9bfe7e17567d4fbe
Status affected
Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7
Version < 9a82dcd98b6e6e11cfd162410967951f12152528
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.23
Status affected
Version 0
Version < 2.6.23
Status unaffected
Version <= 5.10.*
Version 5.10.266
Status unaffected
Version <= 5.15.*
Version 5.15.217
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.153
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.112
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/2002ff745db64ac83ee1bb9ff78196d2d68bfdb3
https://git.kernel.org/stable/c/38d91446630a20ce8c2a981810deea81fd61a3b5
https://git.kernel.org/stable/c/638213f2e6ea52c06a25861616781338d154db35
https://git.kernel.org/stable/c/2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7
https://git.kernel.org/stable/c/a63011c009ea79439b800a05602b880eb4adbb05
https://git.kernel.org/stable/c/acd5b09be98fd38b7392307880156fb0452a7276
https://git.kernel.org/stable/c/1b995966c3ae5244751bdaee9bfe7e17567d4fbe
https://git.kernel.org/stable/c/9a82dcd98b6e6e11cfd162410967951f12152528