selinux: do not cancel a policy conversion that never started

Summary

CVECVE-2026-80756
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-03 13:06:15 UTC
Updated2026-09-03 13:06:15 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: selinux: do not cancel a policy conversion that never started sel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes() fails, and that helper dereferences the outgoing policy to cancel its sidtab conversion. On the first policy load there is no outgoing policy: security_load_policy() returns early for that case, before it converts anything, and state->policy is still NULL. A first load that fails while building the selinuxfs tree therefore takes a NULL dereference in selinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load. Skip the cancel when there is no old policy, mirroring the check security_load_policy() already makes before it converts.

Risk And Classification

EPSS: 0.002100000 probability, percentile 0.112230000 (date 2026-09-07)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 2d29983104f06f5b0babcd5a25a0f0408272cd27 git Not specified
CNA Linux Linux affected 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 a4f182f8715cb0819445f0850cd5436828f4bafc git Not specified
CNA Linux Linux affected 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 1059789ae9f99cbbe3a78e361e9c0976beb5958b git Not specified
CNA Linux Linux affected 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 1acc317d67a755a45e32419a15d70e403fa43f0e git Not specified
CNA Linux Linux affected 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 a42932c6aa33d0aac683cacdf1ec7009b955ba5d git Not specified
CNA Linux Linux affected 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 1b4ff94ae7c580c880291519fb0e3e2bd075beef git Not specified
CNA Linux Linux affected 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 219c96de5d9b6b4af7e8576ad897b774cc3ee9a7 git Not specified
CNA Linux Linux affected 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 e5c0235a3c4e9eb047a16cd02323fe4ecf2f570e git Not specified
CNA Linux Linux affected 5.10 Not specified
CNA Linux Linux unaffected 5.10 semver Not specified
CNA Linux Linux unaffected 5.10.266 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.217 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.184 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.153 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.105 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.46 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.10 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/e5c0235a3c4e9eb047a16cd02323fe4ecf2f570e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a42932c6aa33d0aac683cacdf1ec7009b955ba5d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1059789ae9f99cbbe3a78e361e9c0976beb5958b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1b4ff94ae7c580c880291519fb0e3e2bd075beef 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a4f182f8715cb0819445f0850cd5436828f4bafc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1acc317d67a755a45e32419a15d70e403fa43f0e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/219c96de5d9b6b4af7e8576ad897b774cc3ee9a7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2d29983104f06f5b0babcd5a25a0f0408272cd27 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report