PT-2026-43921 · Linux · Linux Kernel
Published
2026-05-27
·
Updated
2026-06-12
·
CVE-2026-46054
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The SELinux security model for overlayfs allows access if the current task can access the top-level user file and the mounter's credentials are sufficient for the lower-level backing file. However, access controls were not properly enforced for
mmap() and mprotect() operations on overlayfs filesystems. The issue is addressed by using the security mmap backing file() LSM hook for mmap() operations and utilizing the backing file API and a new LSM blob to enforce mprotect() access controls.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel