Out-of-bounds write in Linux kernel - CVE-2026-80755
Published: September 4, 2026
Vulnerability details
The vulnerability allows a local user to perform an out-of-bounds heap write.
The vulnerability exists due to an out-of-bounds write in the SELinux policy permission parser when processing a policy image in which a class declares fewer permissions than its largest permission value. A local user can supply a crafted policy containing such a permission declaration to perform an out-of-bounds heap write.