Home

Description

In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group.

PUBLISHED Reserved 2026-05-13 | Published 2026-05-28 | Updated 2026-06-01 | Assigner Linux




HIGH: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Product status

Default status
unaffected

abc77577a669f424c5d0c185b9994f2621c52aa4 (git) before a24765332e129c1916d5a6615418b75599b8fcdc
affected

abc77577a669f424c5d0c185b9994f2621c52aa4 (git) before 4a7611ad653785fcdea5ff5f4441e2b7d05b7f11
affected

abc77577a669f424c5d0c185b9994f2621c52aa4 (git) before 04bb66be92f48ed13c3faf1139d892df228789bc
affected

abc77577a669f424c5d0c185b9994f2621c52aa4 (git) before 895ebbedf88318607c24acc0f591c74b165e1d0a
affected

abc77577a669f424c5d0c185b9994f2621c52aa4 (git) before f130790f1acc8399f32652846c875a251efd040f
affected

abc77577a669f424c5d0c185b9994f2621c52aa4 (git) before 7baa02b0ae9d17ec5f08836d8ea88ce1927d0678
affected

abc77577a669f424c5d0c185b9994f2621c52aa4 (git) before b7b24b28c8cd55844cab908f4f39dded638d5538
affected

abc77577a669f424c5d0c185b9994f2621c52aa4 (git) before 7746e3bd4cc19b5092e00d32d676e329bfcb6900
affected

Default status
affected

4.12
affected

Any version before 4.12
unaffected

5.10.258 (semver)
unaffected

5.15.209 (semver)
unaffected

6.1.175 (semver)
unaffected

6.6.140 (semver)
unaffected

6.12.88 (semver)
unaffected

6.18.30 (semver)
unaffected

7.0.7 (semver)
unaffected

7.1-rc2 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/a24765332e129c1916d5a6615418b75599b8fcdc

git.kernel.org/...c/4a7611ad653785fcdea5ff5f4441e2b7d05b7f11

git.kernel.org/...c/04bb66be92f48ed13c3faf1139d892df228789bc

git.kernel.org/...c/895ebbedf88318607c24acc0f591c74b165e1d0a

git.kernel.org/...c/f130790f1acc8399f32652846c875a251efd040f

git.kernel.org/...c/7baa02b0ae9d17ec5f08836d8ea88ce1927d0678

git.kernel.org/...c/b7b24b28c8cd55844cab908f4f39dded638d5538

git.kernel.org/...c/7746e3bd4cc19b5092e00d32d676e329bfcb6900

cve.org (CVE-2026-46150)

nvd.nist.gov (CVE-2026-46150)

Download JSON