{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  selinux: preserve user SID across nested backing files  SELinux saves the user file SID in a backing-file security blob so it remains available after mmap() replaces vma-\u003evm_file with a backing file.  For nested backing files (overlayfs over overlayfs, or FUSE passthrough backed by overlayfs), user_file may itself be a backing file.  Its fsec-\u003esid is the SID of the mounter that opened it, rather than the user that opened the top-level file.  mprotect() then checks fd { use } against the mounter SID.  This can incorrectly deny access without a domain transition, or check the wrong target SID after one.  Copy the saved user SID when user_file is a backing file.  Keep using the regular file SID for the first backing layer.  With two nested overlayfs mounts and SELinux enforcing, mprotect(PROT_READ) returns EACCES with an fd { use } denial against the mounter SID.  With this change, mprotect() succeeds.  Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built SELinux policy.  The original test was also repeated with Fedora Cloud Base 44 userspace and gave the same result.",
  "id": "DEBIAN-CVE-2026-98215",
  "modified": "2026-10-07T04:47:31.937905582Z",
  "published": "2026-10-06T09:18:08.107Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98215"
    }
  ],
  "upstream": [
    "CVE-2026-98215"
  ]
}