Vulnerability in OverlayFS on Linux Kernel by the Linux Foundation
CVE-2026-68448
What is CVE-2026-68448?
A vulnerability in OverlayFS within the Linux Kernel enables improper verification of read access permissions during copy operations across different overlay filesystems. This flaw can lead to unintended access being granted to files that should be restricted. Although the system attempts to check permissions using destination overlay filesystem credentials, it fails to adequately verify the rights for source files. This could permit unauthorized file reading, potentially affecting system integrity and data security. It is important for users to be aware of this vulnerability and apply necessary patches to mitigate risks associated with unauthorized file access.
Affected Version(s)
Linux 5dae222a5ff0c269730393018a5539cc970a4726 < 9ec22c8113d8cf72ed7197bb61037dcad09e50d8
Linux 5dae222a5ff0c269730393018a5539cc970a4726 < 1f4a107439d2e43db176e34919933e617cb7f2c5
Linux 5dae222a5ff0c269730393018a5539cc970a4726