CVE-2026-80757

high

Description

In the Linux kernel, the following vulnerability has been resolved: selinux: reject a class permission count below its inherited common security_get_permissions() maps an inherited common's permissions into an array sized by the class's own permissions.nprim, but class_read() takes that nprim verbatim from the policy image and never checks that it covers the common. A class that inherits a common of N permissions while declaring a smaller nprim is accepted, and on load the common's permissions are written past the class-sized array -- an out-of-bounds heap write. Reject a class whose permission count is below its inherited common's. Well-formed policies, where the class count already includes the inherited permissions, are unaffected.

References

https://git.kernel.org/stable/c/acd5b09be98fd38b7392307880156fb0452a7276

https://git.kernel.org/stable/c/a63011c009ea79439b800a05602b880eb4adbb05

https://git.kernel.org/stable/c/9a82dcd98b6e6e11cfd162410967951f12152528

https://git.kernel.org/stable/c/638213f2e6ea52c06a25861616781338d154db35

https://git.kernel.org/stable/c/38d91446630a20ce8c2a981810deea81fd61a3b5

https://git.kernel.org/stable/c/2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7

https://git.kernel.org/stable/c/2002ff745db64ac83ee1bb9ff78196d2d68bfdb3

https://git.kernel.org/stable/c/1b995966c3ae5244751bdaee9bfe7e17567d4fbe

Details

Source: Mitre, NVD

Published: 2026-09-03

Updated: 2026-09-03

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.0021