Linux Kernel SELinux Policy Handling Vulnerability
CVE-2026-80756
What is CVE-2026-80756?
A vulnerability exists in the Linux kernel related to SELinux policy handling. Specifically, during the initial policy load, if the sel_make_policy_nodes() function fails, a subsequent call to selinux_policy_cancel() can result in a NULL dereference due to the absence of an outgoing policy. This oversight may cause a system to crash when attempting to write to /sys/fs/selinux/load without a valid policy in place. By implementing a check to skip the cancellation of the policy when there is no old policy loaded, this vulnerability can be effectively mitigated, enhancing the stability and security of the SELinux framework.
Affected Version(s)
Linux 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 < 2d29983104f06f5b0babcd5a25a0f0408272cd27
Linux 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972
Linux 02a52c5c8c3b8cbad0f12009cde9f36dbefb6972 < 1059789ae9f99cbbe3a78e361e9c0976beb5958b