In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access i…
High CVSS 7.1
Summary
In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on ov…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/82544d36b1729153c8aeb179e84750f0c085d3b1 Patch
- https://git.kernel.org/stable/c/8bacd09f12c27710228562e4d13163e58c5f4a45
- https://git.kernel.org/stable/c/bc6c380c1159de52a252ed11f19a42c47f60a735
- https://git.kernel.org/stable/c/cd0e707a927a70cdfd8bc5a512a9719a87f5ed51 Patch
- https://git.kernel.org/stable/c/d844702198395d3f80222777030f69db6be6b709
- https://access.redhat.com/errata/RHSA-2026:25191
- https://access.redhat.com/errata/RHSA-2026:27811
- https://access.redhat.com/errata/RHSA-2026:27812
- https://access.redhat.com/errata/RHSA-2026:30848
- https://access.redhat.com/security/cve/CVE-2026-46054
- https://bugzilla.redhat.com/show_bug.cgi?id=2482025
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46054.json
Timeline
- nvd_ingest NVD