PT-2026-79600 · Linux · Linux Kernel

CVE-2026-74595

·

Published

2026-08-22

·

Updated

2026-08-27

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the fscrypt ioctl set policy() function where it incorrectly uses &nop mnt idmap when calling inode owner or capable() to verify ownership before setting an encryption policy. In filesystems supporting idmapped mounts, such as ext4 and f2fs, this causes the system to compare the caller's fsuid against the unmapped on-disk owner instead of the mapped owner. Consequently, the legitimate owner may be denied access with an -EACCES error, while an unauthorized caller might be granted permission.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-97224
CVE-2026-74595

Affected Products

Linux Kernel