All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80757: selinux: reject a class permission count below its inherited common
@ 2026-09-03  8:26 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-03  8:26 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

selinux: reject a class permission count below its inherited common

security_get_permissions() maps an inherited common's permissions into
an array sized by the class's own permissions.nprim, but class_read()
takes that nprim verbatim from the policy image and never checks that it
covers the common.  A class that inherits a common of N permissions while
declaring a smaller nprim is accepted, and on load the common's
permissions are written past the class-sized array -- an out-of-bounds
heap write.

Reject a class whose permission count is below its inherited common's.
Well-formed policies, where the class count already includes the
inherited permissions, are unaffected.

The Linux kernel CVE team has assigned CVE-2026-80757 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 5.10.266 with commit 2002ff745db64ac83ee1bb9ff78196d2d68bfdb3
	Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 5.15.217 with commit 38d91446630a20ce8c2a981810deea81fd61a3b5
	Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.1.184 with commit 638213f2e6ea52c06a25861616781338d154db35
	Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.6.153 with commit 2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7
	Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.12.105 with commit a63011c009ea79439b800a05602b880eb4adbb05
	Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 6.18.46 with commit acd5b09be98fd38b7392307880156fb0452a7276
	Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 7.1.10 with commit 1b995966c3ae5244751bdaee9bfe7e17567d4fbe
	Issue introduced in 2.6.23 with commit 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and fixed in 7.2 with commit 9a82dcd98b6e6e11cfd162410967951f12152528

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80757
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	security/selinux/ss/policydb.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/2002ff745db64ac83ee1bb9ff78196d2d68bfdb3
	https://git.kernel.org/stable/c/38d91446630a20ce8c2a981810deea81fd61a3b5
	https://git.kernel.org/stable/c/638213f2e6ea52c06a25861616781338d154db35
	https://git.kernel.org/stable/c/2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7
	https://git.kernel.org/stable/c/a63011c009ea79439b800a05602b880eb4adbb05
	https://git.kernel.org/stable/c/acd5b09be98fd38b7392307880156fb0452a7276
	https://git.kernel.org/stable/c/1b995966c3ae5244751bdaee9bfe7e17567d4fbe
	https://git.kernel.org/stable/c/9a82dcd98b6e6e11cfd162410967951f12152528

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-03  8:27 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03  8:26 CVE-2026-80757: selinux: reject a class permission count below its inherited common Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.