Linux kernel SELinux: reject unclaimed class value in security_get_classes()
CVE-2026-80912 Published on September 4, 2026
selinux: reject an unclaimed class value in security_get_classes()
In the Linux kernel, the following vulnerability has been resolved:
selinux: reject an unclaimed class value in security_get_classes()
security_get_classes() sizes an array by p_classes.nprim and fills it at
value - 1, so a class value the policy never defines leaves a NULL.
sel_make_classes() passes every entry to sel_make_dir(), reaching the same
d_alloc_name() dereference as the permission array. The class symbol table
is allowed to be sparse (policydb_class_isvalid() exists to absorb that),
but this getter builds its own array straight from the hash table and has
no such predicate.
Fail the lookup when a value went unclaimed instead of handing out the
NULL. Conforming policies define every class they declare and are
unaffected.
Products Associated with CVE-2026-80912
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and below e0285bb152211c00900136b66d4b420c14a59094 is affected.
- Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and below 099869e9343a5f8c22b58497f074b34f63cbf856 is affected.
- Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and below 841aea4d5a25e16273d04cd07a74142b4687e03b is affected.
- Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and below d8a10899ea3c84b80de72ca8ee9039e9a5156c9a is affected.
- Version 55fcf09b3fe4325c9395ebbb0322a547a157ebc7 and below 22b05fec62c0fe9864cfceb52f7d0f3a34d9b1dd is affected.
- Version 2.6.23 is affected.
- Before 2.6.23 is unaffected.
- Version 6.6.153, <= 6.6.* is unaffected.
- Version 6.12.105, <= 6.12.* is unaffected.
- Version 6.18.46, <= 6.18.* is unaffected.
- Version 7.1.10, <= 7.1.* is unaffected.
- Version 7.2, <= * is unaffected.