GHSA-fwgc-423f-pq7gMediumCVSS 5.5

In the Linux kernel, the following vulnerability has been resolved: selinux: fix avdcache...

Published
July 19, 2026
Last Modified
July 29, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

selinux: fix avdcache auditing

The per-task avdcache was incorrectly saving and reusing the audited vector computed by avc_audit_required() rather than recomputing based on the currently requested permissions and distinguishing the denied versus allowed cases. As a result, some permission checks were not being audited, e.g. directory write checks after a previously cached directory search check.

[PM: line wrap tweaks]

🔗 References (5)