PT-2026-43921 · Linux · Linux Kernel

Published

2026-05-27

·

Updated

2026-06-12

·

CVE-2026-46054

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The SELinux security model for overlayfs allows access if the current task can access the top-level user file and the mounter's credentials are sufficient for the lower-level backing file. However, access controls were not properly enforced for mmap() and mprotect() operations on overlayfs filesystems. The issue is addressed by using the security mmap backing file() LSM hook for mmap() operations and utilizing the backing file API and a new LSM blob to enforce mprotect() access controls.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:25191
CVE-2026-46054
OPENSUSE-SU-2026:10954-1

Affected Products

Linux Kernel