Junglewise Threat Intelligence

CVE-2026-72379: Linux kernel O_TMPFILE creation with unmapped fsuid/fsgid bypass

CVE-2026-72379 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's filesystem code did not properly validate user ID (uid) and group ID (gid) mappings when creating temporary files on certain mounted filesystems. This could allow files to be created with invalid owners, potentially bypassing security controls that prevent filesystem corruption or data exposure when using identity-mapped mounts.

Technical details

The vulnerability exists in vfs_tmpfile(), which handles the creation of temporary files via the O_TMPFILE flag. Unlike other file creation paths (O_CREAT, mkdir, mknod, symlink, link), vfs_tmpfile() did not check whether the caller's fsuid and fsgid map into the filesystem's idmapping using fsuidgid_has_mapping(). On idmapped mounts that do not cover the caller's fs{u,g}id, the inode would be initialized with INVALID_UID/INVALID_GID, resulting in files owned by (uid_t)-1. The fix adds the missing fsuidgid_has_mapping() check to vfs_tmpfile() to return -EOVERFLOW when the caller's IDs do not map, consistent with other file creation paths. This affects all filesystems supporting FS_ALLOW_IDMAP with ->tmpfile() implementation (tmpfs, ext4, btrfs, xfs, f2fs, etc.) and overlayfs.

Affected products

  • Linux Linux kernel all versions prior to patch 539dce1144651f7976fa418e618b0b574bf15eeb

Timeline

  • 2026-08-15: disclosed
  • 2026-06-15: patched

References

Related threats