-

CVE-2026-98215

selinux: preserve user SID across nested backing files

In the Linux kernel, the following vulnerability has been resolved:

selinux: preserve user SID across nested backing files

SELinux saves the user file SID in a backing-file security blob so it
remains available after mmap() replaces vma->vm_file with a backing file.

For nested backing files (overlayfs over overlayfs, or FUSE passthrough
backed by overlayfs), user_file may itself be a backing file.  Its
fsec->sid is the SID of the mounter that opened it, rather than the user
that opened the top-level file.  mprotect() then checks fd { use } against
the mounter SID.  This can incorrectly deny access without a domain
transition, or check the wrong target SID after one.

Copy the saved user SID when user_file is a backing file.  Keep using the
regular file SID for the first backing layer.

With two nested overlayfs mounts and SELinux enforcing,
mprotect(PROT_READ) returns EACCES with an fd { use } denial against the
mounter SID.  With this change, mprotect() succeeds.

Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built
SELinux policy.  The original test was also repeated with Fedora Cloud
Base 44 userspace and gave the same result.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bc6c380c1159de52a252ed11f19a42c47f60a735
Version < caa1b913d90d5dc07073733326d2af0f0288f089
Status affected
Version 8bacd09f12c27710228562e4d13163e58c5f4a45
Version < 6aaeec59aadcd1eafc18b049f1b759fb6b9d9569
Status affected
Version d844702198395d3f80222777030f69db6be6b709
Version < 9d99b770e7b67b00bdef9005b928aad13e1d679b
Status affected
Version 82544d36b1729153c8aeb179e84750f0c085d3b1
Version < ff20d16b2e8230c034e21540043df47222dcc09b
Status affected
Version 82544d36b1729153c8aeb179e84750f0c085d3b1
Version < 8c0c602202b9a4909b00bc3354e3c0355bc69e65
Status affected
Version cd0e707a927a70cdfd8bc5a512a9719a87f5ed51
Status affected
Version 6.6.144
Version < 6.6.158
Status affected
Version 6.12.95
Version < 6.12.112
Status affected
Version 6.18.38
Version < 6.18.54
Status affected
Version 7.0.4
Version < 7.1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.1
Status affected
Version 0
Version < 7.1
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/caa1b913d90d5dc07073733326d2af0f0288f089
https://git.kernel.org/stable/c/6aaeec59aadcd1eafc18b049f1b759fb6b9d9569
https://git.kernel.org/stable/c/9d99b770e7b67b00bdef9005b928aad13e1d679b
https://git.kernel.org/stable/c/ff20d16b2e8230c034e21540043df47222dcc09b
https://git.kernel.org/stable/c/8c0c602202b9a4909b00bc3354e3c0355bc69e65