Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

ubuntu логотип

CVE-2026-46054

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-46054

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2026-46054

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2026-46054

2 месяца назад

selinux: fix overlayfs mmap() and mprotect() access checks

EPSS: Низкий
debian логотип

CVE-2026-46054

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: s ...

CVSS3: 7.1
EPSS: Низкий
rocky логотип

RLSA-2026:27811

около 1 месяца назад

Important: kernel security update

EPSS: Низкий
github логотип

GHSA-xg2q-7399-f2r3

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.

CVSS3: 7.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-27811

около 1 месяца назад

ELSA-2026-27811: kernel security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:25191

около 2 месяцев назад

Critical: kernel security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-25191

16 дней назад

ELSA-2026-25191: kernel security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-30848

25 дней назад

ELSA-2026-30848: kernel security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-46054

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.

CVSS3: 7.1
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-46054

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.

CVSS3: 7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-46054

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.

CVSS3: 7.1
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-46054

selinux: fix overlayfs mmap() and mprotect() access checks

0%
Низкий
2 месяца назад
debian логотип
CVE-2026-46054

In the Linux kernel, the following vulnerability has been resolved: s ...

CVSS3: 7.1
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:27811

Important: kernel security update

0%
Низкий
около 1 месяца назад
github логотип
GHSA-xg2q-7399-f2r3

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.

CVSS3: 7.1
0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-27811

ELSA-2026-27811: kernel security update (IMPORTANT)

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:25191

Critical: kernel security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-25191

ELSA-2026-25191: kernel security update (CRITICAL)

16 дней назад
oracle-oval логотип
ELSA-2026-30848

ELSA-2026-30848: kernel security, bug fix, and enhancement update (IMPORTANT)

25 дней назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.