Answer in brief
CVE-2026-98215 records a Unknown severity vulnerability in selinux: preserve user SID across nested backing files. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bc6c380c1159de52a252ed11f19a42c47f60a735 <caa1b913d90d5dc07073733326d2af0f0288f089 || >=8bacd09f12c27710228562e4d13163e58c5f4a45 <6aaeec59aadcd1eafc18b049f1b759fb6b9d9569 || >=d844702198395d3f80222777030f69db6be6b709 <9d99b770e7b67b00bdef9005b928aad13e1d679b || >=82544d36b1729153c8aeb179e84750f0c085d3b1 <ff20d16b2e8230c034e21540043df47222dcc09b || >=82544d36b1729153c8aeb179e84750f0c085d3b1 <8c0c602202b9a4909b00bc3354e3c0355bc69e65 || cd0e707a927a70cdfd8bc5a512a9719a87f5ed51 || >=6.6.144 <6.6.158 || >=6.12.95 <6.12.112 || >=6.18.38 <6.18.54 || >=7.0.4 <7.1 | caa1b913d90d5dc07073733326d2af0f0288f089, 6aaeec59aadcd1eafc18b049f1b759fb6b9d9569, 9d99b770e7b67b00bdef9005b928aad13e1d679b, ff20d16b2e8230c034e21540043df47222dcc09b, 8c0c602202b9a4909b00bc3354e3c0355bc69e65, 6.6.158, 6.12.112, 6.18.54, 7.1 |
| Linux/Linuxgeneric | 7.1 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: selinux: preserve user SID across nested backing files SELinux saves the user file SID in a backing-file security blob so it remains available after mmap() replaces vma->vm_file with a backing file. For nested backing files (overlayfs over overlayfs, or FUSE passthrough backed by overlayfs), user_file may itself be a backing file. Its fsec->sid is the SID of the mounter that opened it, rather than the user that opened the top-level file. mprotect() then checks fd { use } against the mounter SID. This can incorrectly deny access without a domain transition, or check the wrong target SID after one. Copy the saved user SID when user_file is a backing file. Keep using the regular file SID for the first backing layer. With two nested overlayfs mounts and SELinux enforcing, mprotect(PROT_READ) returns EACCES with an fd { use } denial against the mounter SID. With this change, mprotect() succeeds. Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built SELinux policy. The original test was also repeated with Fedora Cloud Base 44 userspace and gave the same result.
Quoted source text, attributed separately from HOL analysis.