CVE-2026-74595
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/08/2026
Last modified:
23/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()<br />
<br />
fscrypt_ioctl_set_policy() calls inode_owner_or_capable() with<br />
&nop_mnt_idmap before allowing an encryption policy to be set, instead<br />
of the idmap of the mount the ioctl was issued on.<br />
<br />
fscrypt is used by filesystems that support idmapped mounts (e.g. ext4,<br />
f2fs), so on such a mount this compares the caller&#39;s fsuid against the<br />
unmapped on-disk owner rather than the mapped owner: the actual owner<br />
can be wrongly denied with -EACCES and an unrelated caller wrongly<br />
allowed. Use file_mnt_idmap(filp) instead.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0baeb730044981f5ec5fb7d62a3763835ea606f6
- https://git.kernel.org/stable/c/174633a468817a49bd474bcfc9067c84e54efe68
- https://git.kernel.org/stable/c/33b7e810ce09955aa02f3b632455cf5e7ac990a9
- https://git.kernel.org/stable/c/653e888a24c87b8bbeab44d7e558a1c1a3641088
- https://git.kernel.org/stable/c/6a67c460b12315033268dce597546984fe5739e7
- https://git.kernel.org/stable/c/98516ba8b817f34e86bdd7a5b7a383cff75c3ddf
- https://git.kernel.org/stable/c/cf6c993c0feca7984797e634deba3c80342e199a


