---
id: CVE-2026-46302
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  selinux: allow multiple opens of /sys/fs/selinux/policy

  Currently there can only be a single open of /sys/fs/selinux/policy at
  any time
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  selinux: allow multiple opens of /sys/fs/selinux/policy

  Currently there can only be a single open of /sys/fs/selinux/policy at
  any time. This allows any process to blo…
severity: none
published: '2026-06-08'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46302'
references:
  - url: 'https://git.kernel.org/stable/c/714362f3779dfa453a78ced32396a72726962a41'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a02cd6805562305f936e807da83e253b719dd965'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.001
epssPercentile: 0.00969
ingestedAt: '2026-07-07T18:42:24.325Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

selinux: allow multiple opens of /sys/fs/selinux/policy

Currently there can only be a single open of /sys/fs/selinux/policy at
any time. This allows any process to block any other process from
reading the kernel policy. The original motivation seems to have been
a mix of preventing an inconsistent view of the policy size and
preventing userspace from allocating kernel memory without bound, but
this is arguably equally bad. Eliminate the policy_opened flag and
shrink the critical section that the policy mutex is held. While we
are making changes here, drop a couple of extraneous BUG_ONs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
