CVE-2026-46054

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

04 Jul 2026, 12:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/8bacd09f12c27710228562e4d13163e58c5f4a45 -
  • () https://git.kernel.org/stable/c/bc6c380c1159de52a252ed11f19a42c47f60a735 -
  • () https://git.kernel.org/stable/c/d844702198395d3f80222777030f69db6be6b709 -

30 Jun 2026, 03:20

Type Values Removed Values Added
CWE CWE-280
References
  • () https://access.redhat.com/errata/RHSA-2026:25191 -
  • () https://access.redhat.com/errata/RHSA-2026:27811 -
  • () https://access.redhat.com/errata/RHSA-2026:27812 -
  • () https://access.redhat.com/errata/RHSA-2026:30848 -
  • () https://access.redhat.com/security/cve/CVE-2026-46054 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2482025 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46054.json -

16 Jun 2026, 15:02

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/82544d36b1729153c8aeb179e84750f0c085d3b1 - () https://git.kernel.org/stable/c/82544d36b1729153c8aeb179e84750f0c085d3b1 - Patch
References () https://git.kernel.org/stable/c/cd0e707a927a70cdfd8bc5a512a9719a87f5ed51 - () https://git.kernel.org/stable/c/cd0e707a927a70cdfd8bc5a512a9719a87f5ed51 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Linux linux Kernel
Linux

30 May 2026, 11:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

27 May 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 14:17

Updated : 2026-07-21 12:18


NVD link : CVE-2026-46054

Mitre link : CVE-2026-46054

CVE.ORG link : CVE-2026-46054


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
NVD-CWE-noinfo CWE-280

Improper Handling of Insufficient Permissions or Privileges