* CVE-2026-80757: selinux: reject a class permission count below its inherited common
@ 2026-09-03 8:26 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-03 8:26 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
selinux: reject a class permission count below its inherited common
security_get_permissions() maps an inherited common's permissions into
an array sized by the class's own permissions.nprim, but class_read()
takes that nprim verbatim from the policy image and never checks that it
covers the common. A class that inherits a common of N permissions while
declaring a smaller nprim is accepted, and on load the common's
permissions are written past the class-sized array -- an out-of-bounds
heap write.
Reject a class whose permission count is below its inherited common's.
Well-formed policies, where the class count already includes the
inherited permissions, are unaffected.
The Linux kernel CVE team has assigned CVE-2026-80757 to this issue.
Affected and fixed versions
===========================
Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 5.10.266 with commit 2002ff745db64ac83ee1bb9ff78196d2d68bfdb3
Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 5.15.217 with commit 38d91446630a20ce8c2a981810deea81fd61a3b5
Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.1.184 with commit 638213f2e6ea52c06a25861616781338d154db35
Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.6.153 with commit 2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7
Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.12.105 with commit a63011c009ea79439b800a05602b880eb4adbb05
Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.18.46 with commit acd5b09be98fd38b7392307880156fb0452a7276
Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 7.1.10 with commit 1b995966c3ae5244751bdaee9bfe7e17567d4fbe
Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 7.2 with commit 9a82dcd98b6e6e11cfd162410967951f12152528
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80757
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
security/selinux/ss/policydb.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/2002ff745db64ac83ee1bb9ff78196d2d68bfdb3
https://git.kernel.org/stable/c/38d91446630a20ce8c2a981810deea81fd61a3b5
https://git.kernel.org/stable/c/638213f2e6ea52c06a25861616781338d154db35
https://git.kernel.org/stable/c/2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7
https://git.kernel.org/stable/c/a63011c009ea79439b800a05602b880eb4adbb05
https://git.kernel.org/stable/c/acd5b09be98fd38b7392307880156fb0452a7276
https://git.kernel.org/stable/c/1b995966c3ae5244751bdaee9bfe7e17567d4fbe
https://git.kernel.org/stable/c/9a82dcd98b6e6e11cfd162410967951f12152528
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-03 8:27 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03 8:26 CVE-2026-80757: selinux: reject a class permission count below its inherited common Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.