Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Selinux Project

First CVE: May 23, 2008Active for: 18 yearsTotal CVEs: 13

SELinux Project maintains a mandatory access control framework and associated policy tools that are foundational to Linux security architecture, despite a narrow product scope. Its vulnerabilities center on memory-safety and privilege-escalation issues—use-after-free conditions, improper access control, symlink-following flaws, and out-of-bounds reads—that recur across core components including SELinux itself, setroubleshoot, and policycoreutils, reflecting the low-level kernel integration and administrative privilege these tools demand. Defenders should treat SELinux updates as part of their core OS patching discipline, particularly on systems relying on SELinux policy enforcement for workload isolation; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 91% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.2
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Selinux Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 23, 2008
18 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-1815HIGH
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file
Mar 30, 201510.045NOYES
CVE-2026-59677MEDIUM
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in un
Jul 23, 20266.830NONO
CVE-2026-59676MEDIUM
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux
Jul 23, 20265.827NONO
CVE-2016-7545HIGH
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
Jan 19, 20178.823NONO
CVE-2018-1063MEDIUM
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a con
Mar 2, 20184.418NONO
CVE-2014-3215MEDIUM
seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the setuid system call and the getre
May 8, 20146.918NONO
CVE-2021-36087LOW
The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack
Jul 1, 20213.316NONO
CVE-2021-36086LOW
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
Jul 1, 20213.316NONO
CVE-2021-36085LOW
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map).
Jul 1, 20213.316NONO
CVE-2021-36084LOW
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper).
Jul 1, 20213.316NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
38%
46%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local9 (69.2%)
Network0 (0.0%)
Unknown4 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (61.5%)
High1 (7.7%)
Unknown4 (30.8%)
User Interaction
None8 (61.5%)
Unknown4 (30.8%)
Required1 (7.7%)
Privileges Required
Low8 (61.5%)
High0 (0.0%)
None1 (7.7%)
Unknown4 (30.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Selinux Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Selinux Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Selinux Project's Products

View all 3 CNAs →

Top CWEs