Junglewise Threat Intelligence

CVE-2026-53367: Linux Kernel SELinux missing audit logs due to avdcache logic error

CVE-2026-53367 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A security issue was identified in the Linux kernel's SELinux subsystem, which is responsible for enforcing security policies. Due to a technical error in how the system remembers recent security decisions, some actions—such as writing to a directory—might not be properly recorded in security logs if a different action was recently performed on that same directory. While this does not allow unauthorized access, it prevents security administrators from having a complete and accurate audit trail of system activity.

Technical details

A vulnerability in the SELinux 'avdcache' (Access Vector Decision cache) caused incorrect auditing of permission checks. The per-task cache was saving and reusing the audited vector from 'avc_audit_required()' instead of recomputing it based on the specific requested permissions and distinguishing between allowed and denied cases. This logic error meant that if a task performed a directory search (cached) and subsequently a directory write, the write might not be audited. The fix involves updating 'task_avdcache_update' to store the full 'av_decision' struct and ensuring 'avc_audit_required' is called with current parameters during cache hits. This has been patched in various stable branches including 6.18.30 and 7.0.7.

Affected products

  • Linux Linux 6.18 through 6.18.29, 7.0 through 7.0.6

Timeline

  • 2026-04-10: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References