From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AEE96439341 for ; Thu, 3 Sep 2026 08:27:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788424036; cv=none; b=cdkT49Mk82fI7Yd3jq22Aw/OtJUcmU2AUH3iVGURS7txX20HAkM/SlJs16P5iONM/Z+anWYCP1/x+Dv5GilNFU9IAHhiaMrN0TbCXIInU9HUnzPQRPmM8I49e6AEnALoYYQQoHGJf+WygzWUvTeo2Gqo80D7STxL9ChOc64Pe9o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788424036; c=relaxed/simple; bh=LwSO52KlnSrQIDhaQDidc0GqJN8eaW4FqsYGFoCTuKg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=O83GQxNj0vwIilm3SoMRuBh0/1kNIjFsH2v8I4GP6hxeHlcdn19ae7OwfBDiYzFHtRfhVmxIIhmkcMVPTL8Bu0Ks2nt+eThGcTT2LmwnyfrgptRsimOjJtDUa434V8Fk5fSJSaniB1iuXeSV7Cp71k0tGYJe+STq/L2qF6y7QM4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=QD41yyp7; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="QD41yyp7" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 072A61F000E9; Thu, 3 Sep 2026 08:27:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788424034; bh=gF6SSXooHV/aEYuR4QlIMPjnG8ZwPO7HlEvCX+oo9VA=; h=From:To:Cc:Subject:Date:Reply-To; b=QD41yyp7F8MPNoHdeQe4U6JZKDue3KebUNRfA5ZeNmCA7hrd4C2ykHe4PTpXk03SB 1l8c+MWUHJBL7GXr73r3Q4sb003dMBch7KTm998ZGe4qqaUoHI497gQ9xBpu3FKZxC P/QxegqP7oq94tIHtZhi7JG+eeZMLxMb6iUxIlCU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80757: selinux: reject a class permission count below its inherited common Date: Thu, 3 Sep 2026 10:26:54 +0200 Message-ID: <2026090340-CVE-2026-80757-4253@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3793; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=0gfRdYgr2g+JDKJfhajUJYQxinP/2tQtLGpGyxanhaQ=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkz9R1an/a1LBQ/bGDFaNLx4sGJ+ZOZkpU+6R/o/urrt d9K4vWxjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZgIWwzDgu77bsY3jrss+hCw sPY1qyODzp7SKwwLJgQu+L++l5XXrHRm8X/jK1373PILAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: selinux: reject a class permission count below its inherited common security_get_permissions() maps an inherited common's permissions into an array sized by the class's own permissions.nprim, but class_read() takes that nprim verbatim from the policy image and never checks that it covers the common. A class that inherits a common of N permissions while declaring a smaller nprim is accepted, and on load the common's permissions are written past the class-sized array -- an out-of-bounds heap write. Reject a class whose permission count is below its inherited common's. Well-formed policies, where the class count already includes the inherited permissions, are unaffected. The Linux kernel CVE team has assigned CVE-2026-80757 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 5.10.266 with commit 2002ff745db64ac83ee1bb9ff78196d2d68bfdb3 Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 5.15.217 with commit 38d91446630a20ce8c2a981810deea81fd61a3b5 Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.1.184 with commit 638213f2e6ea52c06a25861616781338d154db35 Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.6.153 with commit 2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7 Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.12.105 with commit a63011c009ea79439b800a05602b880eb4adbb05 Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.18.46 with commit acd5b09be98fd38b7392307880156fb0452a7276 Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 7.1.10 with commit 1b995966c3ae5244751bdaee9bfe7e17567d4fbe Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 7.2 with commit 9a82dcd98b6e6e11cfd162410967951f12152528 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80757 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: security/selinux/ss/policydb.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/2002ff745db64ac83ee1bb9ff78196d2d68bfdb3 https://git.kernel.org/stable/c/38d91446630a20ce8c2a981810deea81fd61a3b5 https://git.kernel.org/stable/c/638213f2e6ea52c06a25861616781338d154db35 https://git.kernel.org/stable/c/2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7 https://git.kernel.org/stable/c/a63011c009ea79439b800a05602b880eb4adbb05 https://git.kernel.org/stable/c/acd5b09be98fd38b7392307880156fb0452a7276 https://git.kernel.org/stable/c/1b995966c3ae5244751bdaee9bfe7e17567d4fbe https://git.kernel.org/stable/c/9a82dcd98b6e6e11cfd162410967951f12152528