CVE-2026-98215
Received
Received - Intake
SELinux user SID preservation in nested backing files
Vulnerability report for CVE-2026-98215, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
selinux: preserve user SID across nested backing files
SELinux saves the user file SID in a backing-file security blob so it
remains available after mmap() replaces vma->vm_file with a backing file.
For nested backing files (overlayfs over overlayfs, or FUSE passthrough
backed by overlayfs), user_file may itself be a backing file. Its
fsec->sid is the SID of the mounter that opened it, rather than the user
that opened the top-level file. mprotect() then checks fd { use } against
the mounter SID. This can incorrectly deny access without a domain
transition, or check the wrong target SID after one.
Copy the saved user SID when user_file is a backing file. Keep using the
regular file SID for the first backing layer.
With two nested overlayfs mounts and SELinux enforcing,
mprotect(PROT_READ) returns EACCES with an fd { use } denial against the
mounter SID. With this change, mprotect() succeeds.
Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built
SELinux policy. The original test was also repeated with Fedora Cloud
Base 44 userspace and gave the same result.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | bc6c380c1159de52a252ed11f19a42c47f60a735 |
| Linux | Linux | 8bacd09f12c27710228562e4d13163e58c5f4a45 |
| Linux | Linux | d844702198395d3f80222777030f69db6be6b709 |
| Linux | Linux | 82544d36b1729153c8aeb179e84750f0c085d3b1 |
| Linux | Linux | 82544d36b1729153c8aeb179e84750f0c085d3b1 |
| Linux | Linux | cd0e707a927a70cdfd8bc5a512a9719a87f5ed51 |
| Linux | Linux | 6.6.144 |
| Linux | Linux | 6.12.95 |
| Linux | Linux | 6.18.38 |
| Linux | Linux | 7.0.4 |
| Linux | Linux | 7.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |