Executive brief
A vulnerability in the Linux kernel's fanotify subsystem could allow certain security permission checks to be bypassed. Fanotify is a system used by security software to monitor and approve file access. An exploit could allow unauthorized file operations that should have been blocked by security monitoring tools.
Technical details
A vulnerability in the Linux kernel's fanotify subsystem arises because fsnotify_get_mark_safe() may return false for a mark belonging to an unrelated group. This occurs during the handling of permission events when the kernel attempts to pin marks before dropping the SRCU lock. If the function incorrectly returns false for a detached mark not in the current group, it can result in the bypass of intended permission checks. The fix involves updating fsnotify_prepare_user_wait() to skip over detached marks that are not part of the current group, ensuring the iteration continues correctly. This issue was introduced by the framework for dropping SRCU locks in event handlers.
Affected products
- Linux Linux Kernel All versions prior to the fix in May 2026
Timeline
- 2026-04-10: other: Patch authored
- 2026-05-28: disclosed: CVE published
- 2026-05-28: patched: Fixes merged into stable branches
References
- https://git.kernel.org/stable/c/7746e3bd4cc19b5092e00d32d676e329bfcb6900
- https://git.kernel.org/stable/c/7baa02b0ae9d17ec5f08836d8ea88ce1927d0678
- https://git.kernel.org/stable/c/895ebbedf88318607c24acc0f591c74b165e1d0a
- https://git.kernel.org/stable/c/b7b24b28c8cd55844cab908f4f39dded638d5538
- https://git.kernel.org/stable/c/f130790f1acc8399f32652846c875a251efd040f