PT-2026-79600 · Linux · Linux Kernel
CVE-2026-74595
·
Published
2026-08-22
·
Updated
2026-08-27
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
fscrypt ioctl set policy() function where it incorrectly uses &nop mnt idmap when calling inode owner or capable() to verify ownership before setting an encryption policy. In filesystems supporting idmapped mounts, such as ext4 and f2fs, this causes the system to compare the caller's fsuid against the unmapped on-disk owner instead of the mapped owner. Consequently, the legitimate owner may be denied access with an -EACCES error, while an unauthorized caller might be granted permission.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel