PT-2026-106544 · Linux · Linux

CVE-2026-98215

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
selinux: preserve user SID across nested backing files
SELinux saves the user file SID in a backing-file security blob so it remains available after mmap() replaces vma->vm file with a backing file.
For nested backing files (overlayfs over overlayfs, or FUSE passthrough backed by overlayfs), user file may itself be a backing file. Its fsec->sid is the SID of the mounter that opened it, rather than the user that opened the top-level file. mprotect() then checks fd { use } against the mounter SID. This can incorrectly deny access without a domain transition, or check the wrong target SID after one.
Copy the saved user SID when user file is a backing file. Keep using the regular file SID for the first backing layer.
With two nested overlayfs mounts and SELinux enforcing, mprotect(PROT READ) returns EACCES with an fd { use } denial against the mounter SID. With this change, mprotect() succeeds.
Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built SELinux policy. The original test was also repeated with Fedora Cloud Base 44 userspace and gave the same result.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98215

Affected Products

Linux