In the Linux kernel, the following vulnerability has been resolved:
selinux: reject an unclaimed class value in securitygetclasses()
securitygetclasses() sizes an array by pclasses.nprim and fills it at value - 1, so a class value the policy never defines leaves a NULL. selmakeclasses() passes every entry to selmakedir(), reaching the same dallocname() dereference as the permission array. The class symbol table is allowed to be sparse (policydbclass_isvalid() exists to absorb that), but this getter builds its own array straight from the hash table and has no such predicate.
Fail the lookup when a value went unclaimed instead of handing out the NULL. Conforming policies define every class they declare and are unaffected.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80912.json"
}