CVE detail
CVE-2026-46054
In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file). Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems. This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
Information published.
vendormsrc.microsoft.comMay 28, 2026, 8:04 AM- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46054.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 27, 2026, 2:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2482025bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 27, 2026, 2:17 PM - https://access.redhat.com/security/cve/CVE-2026-46054access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:30848access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:27812access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:27811access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:17 PM - https://access.redhat.com/errata/RHSA-2026:25191access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 27, 2026, 2:17 PM No excerpt available.
Vendor Advisorygit.kernel.orgMay 27, 2026, 2:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 27, 2026, 2:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 27, 2026, 2:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 27, 2026, 2:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 27, 2026, 2:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-46708CVSS 4.3 · Medium
Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.
- CVE-2024-51459CVSS 8.4 · High
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.
- CVE-2023-0181CVSS 7.1 · High
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to deni…
- CVE-2022-21814CVSS 6.1 · Medium
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of insufficient permissions or privileges may allow an unprivile…
- CVE-2026-11804CVSS 5.2 · Medium
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linu…
- CVE-2026-62393CVSS 4.3 · Medium
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to…