---
id: CVE-2026-98215
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  selinux: preserve user SID across nested backing files

  SELinux saves the user file SID in a backing-file security blob so it
  remains available after mmap() replaces vm…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  selinux: preserve user SID across nested backing files

  SELinux saves the user file SID in a backing-file security blob so it
  remains available after mmap() replaces vm…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= bc6c380c1159de52a252ed11f19a42c47f60a735 <
    caa1b913d90d5dc07073733326d2af0f0288f089
  - >-
    Linux >= 8bacd09f12c27710228562e4d13163e58c5f4a45 <
    6aaeec59aadcd1eafc18b049f1b759fb6b9d9569
  - >-
    Linux >= d844702198395d3f80222777030f69db6be6b709 <
    9d99b770e7b67b00bdef9005b928aad13e1d679b
  - >-
    Linux >= 82544d36b1729153c8aeb179e84750f0c085d3b1 <
    ff20d16b2e8230c034e21540043df47222dcc09b
  - >-
    Linux >= 82544d36b1729153c8aeb179e84750f0c085d3b1 <
    8c0c602202b9a4909b00bc3354e3c0355bc69e65
  - Linux cd0e707a927a70cdfd8bc5a512a9719a87f5ed51
  - Linux >= 6.6.144 < 6.6.158
  - Linux >= 6.12.95 < 6.12.112
  - Linux >= 6.18.38 < 6.18.54
  - Linux >= 7.0.4 < 7.1
  - Linux 7.1
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:08.107'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98215'
references:
  - url: 'https://git.kernel.org/stable/c/6aaeec59aadcd1eafc18b049f1b759fb6b9d9569'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8c0c602202b9a4909b00bc3354e3c0355bc69e65'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9d99b770e7b67b00bdef9005b928aad13e1d679b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/caa1b913d90d5dc07073733326d2af0f0288f089'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ff20d16b2e8230c034e21540043df47222dcc09b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.441Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

selinux: preserve user SID across nested backing files

SELinux saves the user file SID in a backing-file security blob so it
remains available after mmap() replaces vma->vm_file with a backing file.

For nested backing files (overlayfs over overlayfs, or FUSE passthrough
backed by overlayfs), user_file may itself be a backing file.  Its
fsec->sid is the SID of the mounter that opened it, rather than the user
that opened the top-level file.  mprotect() then checks fd { use } against
the mounter SID.  This can incorrectly deny access without a domain
transition, or check the wrong target SID after one.

Copy the saved user SID when user_file is a backing file.  Keep using the
regular file SID for the first backing layer.

With two nested overlayfs mounts and SELinux enforcing,
mprotect(PROT_READ) returns EACCES with an fd { use } denial against the
mounter SID.  With this change, mprotect() succeeds.

Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built
SELinux policy.  The original test was also repeated with Fedora Cloud
Base 44 userspace and gave the same result.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
