{"id":"CVE-2026-98215","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: preserve user SID across nested backing files\n\nSELinux saves the user file SID in a backing-file security blob so it\nremains available after mmap() replaces vm…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: preserve user SID across nested backing files\n\nSELinux saves the user file SID in a backing-file security blob so it\nremains available after mmap() replaces vm…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= bc6c380c1159de52a252ed11f19a42c47f60a735 < caa1b913d90d5dc07073733326d2af0f0288f089","Linux >= 8bacd09f12c27710228562e4d13163e58c5f4a45 < 6aaeec59aadcd1eafc18b049f1b759fb6b9d9569","Linux >= d844702198395d3f80222777030f69db6be6b709 < 9d99b770e7b67b00bdef9005b928aad13e1d679b","Linux >= 82544d36b1729153c8aeb179e84750f0c085d3b1 < ff20d16b2e8230c034e21540043df47222dcc09b","Linux >= 82544d36b1729153c8aeb179e84750f0c085d3b1 < 8c0c602202b9a4909b00bc3354e3c0355bc69e65","Linux cd0e707a927a70cdfd8bc5a512a9719a87f5ed51","Linux >= 6.6.144 < 6.6.158","Linux >= 6.12.95 < 6.12.112","Linux >= 6.18.38 < 6.18.54","Linux >= 7.0.4 < 7.1","Linux 7.1"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:08.107","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98215","references":[{"url":"https://git.kernel.org/stable/c/6aaeec59aadcd1eafc18b049f1b759fb6b9d9569","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c0c602202b9a4909b00bc3354e3c0355bc69e65","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d99b770e7b67b00bdef9005b928aad13e1d679b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/caa1b913d90d5dc07073733326d2af0f0288f089","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff20d16b2e8230c034e21540043df47222dcc09b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.441Z","slug":"CVE-2026-98215","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nselinux: preserve user SID across nested backing files\n\nSELinux saves the user file SID in a backing-file security blob so it\nremains available after mmap() replaces vma->vm_file with a backing file.\n\nFor nested backing files (overlayfs over overlayfs, or FUSE passthrough\nbacked by overlayfs), user_file may itself be a backing file.  Its\nfsec->sid is the SID of the mounter that opened it, rather than the user\nthat opened the top-level file.  mprotect() then checks fd { use } against\nthe mounter SID.  This can incorrectly deny access without a domain\ntransition, or check the wrong target SID after one.\n\nCopy the saved user SID when user_file is a backing file.  Keep using the\nregular file SID for the first backing layer.\n\nWith two nested overlayfs mounts and SELinux enforcing,\nmprotect(PROT_READ) returns EACCES with an fd { use } denial against the\nmounter SID.  With this change, mprotect() succeeds.\n\nTested on arm64 QEMU with a small BusyBox initramfs and a purpose-built\nSELinux policy.  The original test was also repeated with Fedora Cloud\nBase 44 userspace and gave the same result.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}