« Volver al listado

CVE-2026-80756

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

selinux: do not cancel a policy conversion that never started

sel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes() fails, and that helper dereferences the outgoing policy to cancel its sidtab conversion. On the first policy load there is no outgoing policy: security_load_policy() returns early for that case, before it converts anything, and state->policy is still NULL. A first load that fails while building the selinuxfs tree therefore takes a NULL dereference in selinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load.

Leer descripción completaMostrar menos

Skip the cancel when there is no old policy, mirroring the check security_load_policy() already makes before it converts.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80756",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
              "lessThan": "2d29983104f06f5b0babcd5a25a0f0408272cd27",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
              "lessThan": "a4f182f8715cb0819445f0850cd5436828f4bafc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
              "lessThan": "1059789ae9f99cbbe3a78e361e9c0976beb5958b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
              "lessThan": "1acc317d67a755a45e32419a15d70e403fa43f0e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
              "lessThan": "a42932c6aa33d0aac683cacdf1ec7009b955ba5d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
              "lessThan": "1b4ff94ae7c580c880291519fb0e3e2bd075beef",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
              "lessThan": "219c96de5d9b6b4af7e8576ad897b774cc3ee9a7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02a52c5c8c3b8cbad0f12009cde9f36dbefb6972",
              "lessThan": "e5c0235a3c4e9eb047a16cd02323fe4ecf2f570e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "security/selinux/ss/services.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.266",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.217",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.184",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.153",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.105",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.46",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.10",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "security/selinux/ss/services.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-03T13:06:15.360",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1059789ae9f99cbbe3a78e361e9c0976beb5958b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1acc317d67a755a45e32419a15d70e403fa43f0e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1b4ff94ae7c580c880291519fb0e3e2bd075beef",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/219c96de5d9b6b4af7e8576ad897b774cc3ee9a7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2d29983104f06f5b0babcd5a25a0f0408272cd27",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a42932c6aa33d0aac683cacdf1ec7009b955ba5d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a4f182f8715cb0819445f0850cd5436828f4bafc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e5c0235a3c4e9eb047a16cd02323fe4ecf2f570e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: do not cancel a policy conversion that never started\n\nsel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes()\nfails, and that helper dereferences the outgoing policy to cancel its\nsidtab conversion. On the first policy load there is no outgoing policy:\nsecurity_load_policy() returns early for that case, before it converts\nanything, and state->policy is still NULL. A first load that fails while\nbuilding the selinuxfs tree therefore takes a NULL dereference in\nselinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load.\n\nSkip the cancel when there is no old policy, mirroring the check\nsecurity_load_policy() already makes before it converts."
    }
  ],
  "lastModified": "2026-09-03T13:06:15.360",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}