selinux: fix avdcache auditing
Summary
| CVE | CVE-2026-53367 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 09:17:01 UTC |
| Updated | 2026-07-19 09:17:01 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: selinux: fix avdcache auditing The per-task avdcache was incorrectly saving and reusing the audited vector computed by avc_audit_required() rather than recomputing based on the currently requested permissions and distinguishing the denied versus allowed cases. As a result, some permission checks were not being audited, e.g. directory write checks after a previously cached directory search check. [PM: line wrap tweaks] |
Risk And Classification
EPSS: 0.001660000 probability, percentile 0.062360000 (date 2026-07-20)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected dde3a5d0f4dce1d1a6095e6b8eeb59b75d28fb3b e3e722ea88e051ae5361dc540c01ba18f87b5ffd git | Not specified |
| CNA | Linux | Linux | affected dde3a5d0f4dce1d1a6095e6b8eeb59b75d28fb3b bce6a32bc888dfebb6a7d4dee454228b71ed8369 git | Not specified |
| CNA | Linux | Linux | affected dde3a5d0f4dce1d1a6095e6b8eeb59b75d28fb3b f92d542577db878acfd21cc18dab23d03023b217 git | Not specified |
| CNA | Linux | Linux | affected 21879b76831fab52f6a615c531f86412c8d3c827 git | Not specified |
| CNA | Linux | Linux | affected 6.17.10 6.18 semver | Not specified |
| CNA | Linux | Linux | affected 6.18 | Not specified |
| CNA | Linux | Linux | unaffected 6.18 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.30 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.7 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/e3e722ea88e051ae5361dc540c01ba18f87b5ffd | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/bce6a32bc888dfebb6a7d4dee454228b71ed8369 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f92d542577db878acfd21cc18dab23d03023b217 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.