Junglewise Threat Intelligence

CVE-2026-74595: Linux kernel fscrypt access control bypass in idmapped mounts

CVE-2026-74595 · Severity: high · CVSS 7.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's filesystem encryption (fscrypt) feature has an access control flaw that incorrectly validates file ownership on idmapped mounts used by filesystems like ext4 and f2fs. The bug causes legitimate owners to be wrongly denied access and unrelated users to gain unexpected access when setting encryption policies, potentially compromising the security model of containerized or virtualized environments using user namespace mapping.

Technical details

The vulnerability exists in the fscrypt_ioctl_set_policy() function, which performs an ownership check via inode_owner_or_capable() but passes &nop_mnt_idmap (a no-op identity map) instead of the actual mount's idmap. On idmapped mounts, this causes the function to compare the caller's fsuid against the unmapped on-disk owner rather than the mapped owner as perceived in that mount namespace. The fix changes the call to use file_mnt_user_ns(filp), correctly applying the mount's identity mapping. The vulnerability allows either denial of service (legitimate owners denied encryption policy changes) or privilege escalation (unrelated users gaining policy-setting rights). Patches have been released across multiple kernel versions.

Affected products

  • Linux Linux Kernel 4.0 through 6.18 (multiple stable series)

Timeline

  • 2026-08-22: disclosed
  • 2026-08-23: patched: Patches released for stable kernel versions via commit 0baeb730044981f5ec5fb7d62a3763835ea606f6 and 174633a468817a49bd474bcfc9067c84e54efe68

References

Related threats