SELinux Project maintains a mandatory access control framework and associated policy tools that are foundational to Linux security architecture, despite a narrow product scope. Its vulnerabilities center on memory-safety and privilege-escalation issues—use-after-free conditions, improper access control, symlink-following flaws, and out-of-bounds reads—that recur across core components including SELinux itself, setroubleshoot, and policycoreutils, reflecting the low-level kernel integration and administrative privilege these tools demand. Defenders should treat SELinux updates as part of their core OS patching discipline, particularly on systems relying on SELinux policy enforcement for workload isolation; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Selinux Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1815HIGH The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file | Mar 30, 2015 | 10.0 | 45 | NO | YES |
CVE-2026-59677MEDIUM A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in
un | Jul 23, 2026 | 6.8 | 30 | NO | NO |
CVE-2026-59676MEDIUM A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux | Jul 23, 2026 | 5.8 | 27 | NO | NO |
CVE-2016-7545HIGH SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call. | Jan 19, 2017 | 8.8 | 23 | NO | NO |
CVE-2018-1063MEDIUM Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a con | Mar 2, 2018 | 4.4 | 18 | NO | NO |
CVE-2014-3215MEDIUM seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the setuid system call and the getre | May 8, 2014 | 6.9 | 18 | NO | NO |
The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack | Jul 1, 2021 | 3.3 | 16 | NO | NO |
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list). | Jul 1, 2021 | 3.3 | 16 | NO | NO |
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map). | Jul 1, 2021 | 3.3 | 16 | NO | NO |
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper). | Jul 1, 2021 | 3.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Selinux Project.
Media articles that mention a CVE ID that affects a product developed by Selinux Project — matched by CVE ID, not by vendor name.