Executive brief
A vulnerability was identified in the Linux kernel's SELinux security module that could lead to incorrect security enforcement. When multiple security modules are used together, the system might read the wrong security data for network sockets, potentially allowing or denying actions incorrectly. This could impact the overall security posture and access control reliability of the operating system.
Technical details
A vulnerability in the Linux kernel's SELinux implementation arises from direct dereferencing of 'sk->sk_security' in the 'sock_has_perm()' and 'nlmsg_sock_has_extended_perms()' functions. This assumes the SELinux socket blob is located at offset zero within the composite LSM socket blob, an assumption that fails in stacked LSM configurations where another module may have allocated storage first. Consequently, SELinux may process incorrect Security Identifiers (SIDs) and class values during Access Vector Cache (AVC) checks. The fix involves using the 'selinux_sock()' accessor to correctly locate the SELinux-specific blob regardless of its offset. The issue was introduced in the netlink xperm support and affects versions 6.13 and newer.
Affected products
- Linux Linux Kernel v6.13+
Timeline
- 2026-04-24: other: Patch authored
- 2026-05-28: disclosed: CVE published