fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()

Summary

CVECVE-2026-74595
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-22 16:16:31 UTC
Updated2026-08-22 16:16:31 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() fscrypt_ioctl_set_policy() calls inode_owner_or_capable() with &nop_mnt_idmap before allowing an encryption policy to be set, instead of the idmap of the mount the ioctl was issued on. fscrypt is used by filesystems that support idmapped mounts (e.g. ext4, f2fs), so on such a mount this compares the caller's fsuid against the unmapped on-disk owner rather than the mapped owner: the actual owner can be wrongly denied with -EACCES and an unrelated caller wrongly allowed. Use file_mnt_idmap(filp) instead.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 14f3db5542e62bcf6fe088a09760ac52d55306c5 33b7e810ce09955aa02f3b632455cf5e7ac990a9 git Not specified
CNA Linux Linux affected 14f3db5542e62bcf6fe088a09760ac52d55306c5 6a67c460b12315033268dce597546984fe5739e7 git Not specified
CNA Linux Linux affected 14f3db5542e62bcf6fe088a09760ac52d55306c5 653e888a24c87b8bbeab44d7e558a1c1a3641088 git Not specified
CNA Linux Linux affected 14f3db5542e62bcf6fe088a09760ac52d55306c5 98516ba8b817f34e86bdd7a5b7a383cff75c3ddf git Not specified
CNA Linux Linux affected 14f3db5542e62bcf6fe088a09760ac52d55306c5 cf6c993c0feca7984797e634deba3c80342e199a git Not specified
CNA Linux Linux affected 5.12 Not specified
CNA Linux Linux unaffected 5.12 semver Not specified
CNA Linux Linux unaffected 6.6.152 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.104 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.45 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.9 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/6a67c460b12315033268dce597546984fe5739e7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/33b7e810ce09955aa02f3b632455cf5e7ac990a9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/98516ba8b817f34e86bdd7a5b7a383cff75c3ddf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/cf6c993c0feca7984797e634deba3c80342e199a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/653e888a24c87b8bbeab44d7e558a1c1a3641088 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report