A flaw in the Linux kernel's SELinux netlink send hook allowed processes to evade required SELinux access checks when multiple netlink messages were bundled into one socket buffer. selinux_netlink_send() examined only the first message, potentially allowing subsequent messages to be transmitted without their message-type permission checks; the behavior differed from systems with SELinux disabled.
The corrective kernel patch iterates through every netlink message in the buffer, validates message lengths, and performs a SELinux permission lookup for each message before allowing transmission. Messages requiring permissions that fail validation are denied; unknown message mappings continue to be logged and are denied when SELinux is enforcing unless unknown permissions are permitted. The fix was prepared for upstream inclusion in the Linux v5.7 release cycle.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Paul Moore disclosed the SELinux/netlink missing-access-check issue to the oss-security mailing list. A corrective patch had been posted to the SELinux mailing list and was expected to be submitted for an upcoming Linux v5.7 release candidate.
Dmitry Vyukov reported that selinux_netlink_send() failed to properly handle multiple netlink messages in a socket buffer, resulting in a missing SELinux access check for the affected case.
A Linux kernel patch changed selinux_netlink_send() to iterate through all complete netlink messages in an skb and perform SELinux permission lookup and enforcement for each message. It also added message-length validation and retained conditional handling for unknown message mappings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.