CVE-2026-98215

Source
https://cve.org/CVERecord?id=CVE-2026-98215
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98215.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98215
Downstream
Published
2026-10-06T08:44:51Z
Modified
2026-10-08T02:52:53Z
Summary
selinux: preserve user SID across nested backing files
Details

In the Linux kernel, the following vulnerability has been resolved:

selinux: preserve user SID across nested backing files

SELinux saves the user file SID in a backing-file security blob so it remains available after mmap() replaces vma->vm_file with a backing file.

For nested backing files (overlayfs over overlayfs, or FUSE passthrough backed by overlayfs), user_file may itself be a backing file. Its fsec->sid is the SID of the mounter that opened it, rather than the user that opened the top-level file. mprotect() then checks fd { use } against the mounter SID. This can incorrectly deny access without a domain transition, or check the wrong target SID after one.

Copy the saved user SID when user_file is a backing file. Keep using the regular file SID for the first backing layer.

With two nested overlayfs mounts and SELinux enforcing, mprotect(PROT_READ) returns EACCES with an fd { use } denial against the mounter SID. With this change, mprotect() succeeds.

Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built SELinux policy. The original test was also repeated with Fedora Cloud Base 44 userspace and gave the same result.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98215.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bc6c380c1159de52a252ed11f19a42c47f60a735
Fixed
caa1b913d90d5dc07073733326d2af0f0288f089
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8bacd09f12c27710228562e4d13163e58c5f4a45
Fixed
6aaeec59aadcd1eafc18b049f1b759fb6b9d9569
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d844702198395d3f80222777030f69db6be6b709
Fixed
9d99b770e7b67b00bdef9005b928aad13e1d679b
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
82544d36b1729153c8aeb179e84750f0c085d3b1
Fixed
ff20d16b2e8230c034e21540043df47222dcc09b
Fixed
8c0c602202b9a4909b00bc3354e3c0355bc69e65
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.6.144
Fixed
6.6.158
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.12.95
Fixed
6.12.112
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.18.38
Fixed
6.18.54
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7.0.4
Fixed
7.1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cd0e707a927a70cdfd8bc5a512a9719a87f5ed51

Affected versions

v6.*
v6.12.100
v6.12.101
v6.12.102
v6.12.103
v6.12.104
v6.12.105
v6.12.106
v6.12.107
v6.12.108
v6.12.109
v6.12.110
v6.12.111
v6.12.95
v6.12.96
v6.12.97
v6.12.98
v6.12.99
v6.18.38
v6.18.39
v6.18.40
v6.18.41
v6.18.42
v6.18.43
v6.18.44
v6.18.45
v6.18.46
v6.18.47
v6.18.48
v6.18.49
v6.18.50
v6.18.51
v6.18.52
v6.18.53
v6.6.144
v6.6.145
v6.6.146
v6.6.147
v6.6.148
v6.6.149
v6.6.150
v6.6.151
v6.6.152
v6.6.153
v6.6.154
v6.6.155
v6.6.156
v6.6.157
v7.*
v7.0.10
v7.0.11
v7.0.12
v7.0.13
v7.0.14
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98215.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98215.json"