{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "bc6c380c1159de52a252ed11f19a42c47f60a735"
            },
            {
              "fixed": "4d50ebe5a27724e020747ffd61a051dec67cb8ec"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "8bacd09f12c27710228562e4d13163e58c5f4a45"
            },
            {
              "fixed": "89376fbfdcc1a728e1775f98752cdd90b0930a00"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "d844702198395d3f80222777030f69db6be6b709"
            },
            {
              "fixed": "d127c7e1f3e1231d8ac8b2738e3f00bea12afe74"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "82544d36b1729153c8aeb179e84750f0c085d3b1"
            },
            {
              "fixed": "c2bbb905af2293549651b614a52ad91e0b462b60"
            },
            {
              "fixed": "78fc54b934bfb2c18aad8154c7302067146946f9"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.6.144"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.12.95"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.18.38"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "7.0.4"
            },
            {
              "fixed": "7.1"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "cd0e707a927a70cdfd8bc5a512a9719a87f5ed51"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98214.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: recheck intermediate backing files on mprotect()\n\nmprotect() can be used to bypass the SELinux checks that mmap() performs\nagainst the intermediate layers of a stacked filesystem.\n\nmmap() checks every backing layer as the request descends through the\nstack.  mprotect() only has the lowest backing file in vma-\u003evm_file, so it\nrechecks the top-level user and the lowest mounter, but skips the mounters\nof every layer in between.  With two nested overlayfs mounts and a policy\ndenying mounter_t -\u003e middle_file_t:file { execute }, a direct\nmmap(PROT_EXEC) is denied:\n\n  avc:  denied  { execute } for  pid=71 comm=\"nested_exec\"\n    path=\"/payload\" dev=\"overlay\" ino=9\n    scontext=user_u:base_r:mounter_t\n    tcontext=user_u:object_r:middle_file_t tclass=file permissive=0\n\nwhile mmap(PROT_NONE) followed by mprotect(PROT_EXEC) succeeds.\n\nPreserve each intermediate path, mounter SID and file-description SID in\nthe backing-file security blob, copying the saved entries when another\nbacking layer is opened.  Allocate the array only for nested backing files,\nand release it and the path references in the backing_file_free hook.\n\nDuring mprotect(), recheck fd { use } and the requested inode permissions\nfor every saved mounter, and include the intermediate layers in the execmod\nchecks.  Policy for nested stacking may then need to grant intermediate\nmounters what a direct mmap() already requires, and execmod on intermediate\nlabels for binaries using text relocations.\n\nTested on arm64 QEMU with a small BusyBox initramfs and a purpose-built\nSELinux policy, on a mainline tree containing\ncommit f2381b546e7e (\"fs: fix user path of nested backing files\").\n\n[PM: subject tweak]",
  "id": "CVE-2026-98214",
  "modified": "2026-10-08T02:30:23.856581727Z",
  "published": "2026-10-06T08:44:50.209Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/4d50ebe5a27724e020747ffd61a051dec67cb8ec"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/78fc54b934bfb2c18aad8154c7302067146946f9"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/89376fbfdcc1a728e1775f98752cdd90b0930a00"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c2bbb905af2293549651b614a52ad91e0b462b60"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d127c7e1f3e1231d8ac8b2738e3f00bea12afe74"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98214.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98214"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "selinux: recheck intermediate backing files on mprotect()"
}