{"id":"CVE-2026-98215","summary":"selinux: preserve user SID across nested backing files","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: preserve user SID across nested backing files\n\nSELinux saves the user file SID in a backing-file security blob so it\nremains available after mmap() replaces vma-\u003evm_file with a backing file.\n\nFor nested backing files (overlayfs over overlayfs, or FUSE passthrough\nbacked by overlayfs), user_file may itself be a backing file.  Its\nfsec-\u003esid is the SID of the mounter that opened it, rather than the user\nthat opened the top-level file.  mprotect() then checks fd { use } against\nthe mounter SID.  This can incorrectly deny access without a domain\ntransition, or check the wrong target SID after one.\n\nCopy the saved user SID when user_file is a backing file.  Keep using the\nregular file SID for the first backing layer.\n\nWith two nested overlayfs mounts and SELinux enforcing,\nmprotect(PROT_READ) returns EACCES with an fd { use } denial against the\nmounter SID.  With this change, mprotect() succeeds.\n\nTested on arm64 QEMU with a small BusyBox initramfs and a purpose-built\nSELinux policy.  The original test was also repeated with Fedora Cloud\nBase 44 userspace and gave the same result.","modified":"2026-10-08T02:52:53.806016587Z","published":"2026-10-06T08:44:51.412Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98215.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/6aaeec59aadcd1eafc18b049f1b759fb6b9d9569"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8c0c602202b9a4909b00bc3354e3c0355bc69e65"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9d99b770e7b67b00bdef9005b928aad13e1d679b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/caa1b913d90d5dc07073733326d2af0f0288f089"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ff20d16b2e8230c034e21540043df47222dcc09b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98215.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98215"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"bc6c380c1159de52a252ed11f19a42c47f60a735"},{"fixed":"caa1b913d90d5dc07073733326d2af0f0288f089"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8bacd09f12c27710228562e4d13163e58c5f4a45"},{"fixed":"6aaeec59aadcd1eafc18b049f1b759fb6b9d9569"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"d844702198395d3f80222777030f69db6be6b709"},{"fixed":"9d99b770e7b67b00bdef9005b928aad13e1d679b"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"82544d36b1729153c8aeb179e84750f0c085d3b1"},{"fixed":"ff20d16b2e8230c034e21540043df47222dcc09b"},{"fixed":"8c0c602202b9a4909b00bc3354e3c0355bc69e65"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6.6.144"},{"fixed":"6.6.158"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6.12.95"},{"fixed":"6.12.112"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6.18.38"},{"fixed":"6.18.54"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"7.0.4"},{"fixed":"7.1"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"cd0e707a927a70cdfd8bc5a512a9719a87f5ed51"}]}],"versions":["v6.6.157","v6.6.156","v6.6.155","v6.6.154","v6.6.153","v6.6.152","v6.6.151","v6.6.150","v6.6.149","v6.6.148","v6.6.147","v6.6.146","v6.6.145","v6.6.144","v6.12.111","v6.12.110","v6.12.109","v6.12.108","v6.12.107","v6.12.106","v6.12.105","v6.12.104","v6.12.103","v6.12.102","v6.12.101","v6.12.100","v6.12.99","v6.12.98","v6.12.97","v6.12.96","v6.12.95","v6.18.53","v6.18.52","v6.18.51","v6.18.50","v6.18.49","v6.18.48","v6.18.47","v6.18.46","v6.18.45","v6.18.44","v6.18.43","v6.18.42","v6.18.41","v6.18.40","v6.18.39","v6.18.38","v7.0.14","v7.0.13","v7.0.12","v7.0.11","v7.0.10","v7.0.9","v7.0.8","v7.0.7","v7.0.6","v7.0.5","v7.0.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98215.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98215.json"}}],"schema_version":"1.9.0"}