In the Linux kernel, the following vulnerability has been resolved:
selinux: reject an unclaimed class value in security_get_classes()
security_get_classes() sizes an array by p_classes.nprim and fills it at
value - 1, so a class value the policy never defines leaves a NULL.
sel_make_classes() passes every entry to sel_make_dir(), reaching the same
d_alloc_name() dereference as the permission array. The class symbol table
is allowed to be sparse (policydb_class_isvalid() exists to absorb that),
but this getter builds its own array straight from the hash table and has
no such predicate.
Fail the lookup when a value went unclaimed instead of handing out the
NULL. Conforming policies define every class they declare and are
unaffected.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 18:18
Updated : 2026-09-14 13:18
NVD link : CVE-2026-80912
Mitre link : CVE-2026-80912
CVE.ORG link : CVE-2026-80912
JSON object : View
Products Affected
No product.
CWE
No CWE.
