Fedora Account System
Red Hat Associate
Red Hat Customer
In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026052822-CVE-2026-46150-c96d@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:42919 https://access.redhat.com/errata/RHSA-2026:42919
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:43307 https://access.redhat.com/errata/RHSA-2026:43307
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:49214 https://access.redhat.com/errata/RHSA-2026:49214
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:49213 https://access.redhat.com/errata/RHSA-2026:49213