PT-2026-43921 · Linux+1 · Linux Kernel+1

CVE-2026-46054

·

Published

2026-05-27

·

Updated

2026-07-24

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The SELinux security model for overlayfs allows access if the current task can access the top-level user file and the mounter's credentials are sufficient for the lower-level backing file. However, access controls were not properly enforced for mmap() and mprotect() operations on overlayfs filesystems. The issue is addressed by using the security mmap backing file() LSM hook for mmap() operations and utilizing the backing file API and a new LSM blob to enforce mprotect() access controls.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25191
ALSA-2026:27811
ALSA-2026:27812
ALSA-2026:30129
ALSA-2026:30848
CVE-2026-46054
ECHO-4CA0-D0DD-E33E
OPENSUSE-SU-2026:10954-1
RHSA-2026:25191
RHSA-2026:27811
RHSA-2026:27812
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8569-1
USN-8603-1

Affected Products

Linux Kernel
Rocky Linux