{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "bc6c380c1159de52a252ed11f19a42c47f60a735"
            },
            {
              "fixed": "caa1b913d90d5dc07073733326d2af0f0288f089"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "8bacd09f12c27710228562e4d13163e58c5f4a45"
            },
            {
              "fixed": "6aaeec59aadcd1eafc18b049f1b759fb6b9d9569"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "d844702198395d3f80222777030f69db6be6b709"
            },
            {
              "fixed": "9d99b770e7b67b00bdef9005b928aad13e1d679b"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "82544d36b1729153c8aeb179e84750f0c085d3b1"
            },
            {
              "fixed": "ff20d16b2e8230c034e21540043df47222dcc09b"
            },
            {
              "fixed": "8c0c602202b9a4909b00bc3354e3c0355bc69e65"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.6.144"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.12.95"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.18.38"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "7.0.4"
            },
            {
              "fixed": "7.1"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "cd0e707a927a70cdfd8bc5a512a9719a87f5ed51"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98215.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: preserve user SID across nested backing files\n\nSELinux saves the user file SID in a backing-file security blob so it\nremains available after mmap() replaces vma-\u003evm_file with a backing file.\n\nFor nested backing files (overlayfs over overlayfs, or FUSE passthrough\nbacked by overlayfs), user_file may itself be a backing file.  Its\nfsec-\u003esid is the SID of the mounter that opened it, rather than the user\nthat opened the top-level file.  mprotect() then checks fd { use } against\nthe mounter SID.  This can incorrectly deny access without a domain\ntransition, or check the wrong target SID after one.\n\nCopy the saved user SID when user_file is a backing file.  Keep using the\nregular file SID for the first backing layer.\n\nWith two nested overlayfs mounts and SELinux enforcing,\nmprotect(PROT_READ) returns EACCES with an fd { use } denial against the\nmounter SID.  With this change, mprotect() succeeds.\n\nTested on arm64 QEMU with a small BusyBox initramfs and a purpose-built\nSELinux policy.  The original test was also repeated with Fedora Cloud\nBase 44 userspace and gave the same result.",
  "id": "CVE-2026-98215",
  "modified": "2026-10-08T02:30:25.072955441Z",
  "published": "2026-10-06T08:44:51.412Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/6aaeec59aadcd1eafc18b049f1b759fb6b9d9569"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8c0c602202b9a4909b00bc3354e3c0355bc69e65"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9d99b770e7b67b00bdef9005b928aad13e1d679b"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/caa1b913d90d5dc07073733326d2af0f0288f089"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ff20d16b2e8230c034e21540043df47222dcc09b"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98215.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98215"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "selinux: preserve user SID across nested backing files"
}