PT-2026-44227 · Linux · Linux

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-46104

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
selinux: use sk blob accessor in socket permission helpers
SELinux socket state lives in the composite LSM socket blob.
sock has perm() and nlmsg sock has extended perms() currently dereference sk->sk security directly, which assumes the SELinux socket blob is at offset zero.
In stacked configurations that assumption does not hold. If another LSM allocates socket blob storage before SELinux, these helpers may read the wrong blob and feed invalid SID and class values into AVC checks.
Use selinux sock() instead of accessing sk->sk security directly.

Related Identifiers

CVE-2026-46104

Affected Products

Linux