{"id":"AZL-106467","summary":"CVE-2026-98214 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: recheck intermediate backing files on mprotect()\n\nmprotect() can be used to bypass the SELinux checks that mmap() performs\nagainst the intermediate layers of a stacked filesystem.\n\nmmap() checks every backing layer as the request descends through the\nstack.  mprotect() only has the lowest backing file in vma-\u003evm_file, so it\nrechecks the top-level user and the lowest mounter, but skips the mounters\nof every layer in between.  With two nested overlayfs mounts and a policy\ndenying mounter_t -\u003e middle_file_t:file { execute }, a direct\nmmap(PROT_EXEC) is denied:\n\n  avc:  denied  { execute } for  pid=71 comm=\"nested_exec\"\n    path=\"/payload\" dev=\"overlay\" ino=9\n    scontext=user_u:base_r:mounter_t\n    tcontext=user_u:object_r:middle_file_t tclass=file permissive=0\n\nwhile mmap(PROT_NONE) followed by mprotect(PROT_EXEC) succeeds.\n\nPreserve each intermediate path, mounter SID and file-description SID in\nthe backing-file security blob, copying the saved entries when another\nbacking layer is opened.  Allocate the array only for nested backing files,\nand release it and the path references in the backing_file_free hook.\n\nDuring mprotect(), recheck fd { use } and the requested inode permissions\nfor every saved mounter, and include the intermediate layers in the execmod\nchecks.  Policy for nested stacking may then need to grant intermediate\nmounters what a direct mmap() already requires, and execmod on intermediate\nlabels for binaries using text relocations.\n\nTested on arm64 QEMU with a small BusyBox initramfs and a purpose-built\nSELinux policy, on a mainline tree containing\ncommit f2381b546e7e (\"fs: fix user path of nested backing files\").\n\n[PM: subject tweak]","modified":"2026-10-09T05:35:24Z","published":"2026-10-06T09:18:07Z","upstream":["CVE-2026-98214"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98214"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106467.json"}}],"schema_version":"1.9.0"}