目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-68448— overlayfs copy_file_range 源文件访问控制漏洞

AI Predicted 4.7 Difficulty: Moderate EPSS 0.15% · P5

Affected Version Matrix 8

ベンダープロダクトVersion Rangeステータス
LinuxLinux5dae222a5ff0c269730393018a5539cc970a4726< 9ec22c8113d8cf72ed7197bb61037dcad09e50d8affected
5dae222a5ff0c269730393018a5539cc970a4726< 1f4a107439d2e43db176e34919933e617cb7f2c5affected
5dae222a5ff0c269730393018a5539cc970a4726< a1e0eb8f55cfe09bb31a202a388babc411292656affected
5.3affected
< 5.3unaffected
6.18.42≤ 6.18.*unaffected
7.1.6≤ 7.1.*unaffected
7.2-rc5≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-68448の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
ovl: check access to copy_file_range source with src mounter creds
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_file_range source with src mounter creds Commit 5dae222a5ff0c ("vfs: allow copy_file_range to copy across devices") allowed filesystems that implement the copy_file_range() f_op to decide if they want to access cross-sb copy from/to the same fs type. The same commit added checks to verify same sb copy for filesystems that implement ->copy_file_range() and do not support cross-sb copy at the time, namely, to ceph, fuse and nfs. The two remaining fs which implement ->copy_file_range(), cifs and overlayfs started to support cross-sb copy from this time. While overlayfs does support cross-sb copy when the two underlying files are on the same base fs, the copy operation on the two real files from two different overalyfs filesystems is performed with the mounter creds of the destination overlayfs and the read permission access hook for the source file was called with the wrong creds. This could cause either deny of access to copy which would otherwise be allowed (e.g. with splice) or allow read access to file which would otherwise be denied. Fix the latter case by explicitly verifying read access to source file with the source overlayfs mounter creds. The former case remains a quirk of cross-sb overlayfs copy, but userspace could fall back to regular copy so no harm done.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 5dae222a5ff0c269730393018a5539cc970a4726 ~ 9ec22c8113d8cf72ed7197bb61037dcad09e50d8 -
LinuxLinux 5.3 -

II. CVE-2026-68448の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-68448のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-68448 补丁与修复 (3)

Same Patch Batch · Linux · 2026-08-12 · 22 CVEs total

CVE-2026-68439wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
CVE-2026-68429drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
CVE-2026-68430drm/amdgpu/gfx8: drop unecessary BUG_ON()
CVE-2026-68431ksmbd: validate minimum PDU size for transform requests
CVE-2026-68432vxlan: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-68433libceph: bound get_version reply decode to front len
CVE-2026-68434serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
CVE-2026-68435LoongArch: Fix address space mismatch in kexec command line lookup
CVE-2026-68436drm/amd/display: use kvzalloc to allocate struct dc
CVE-2026-68437drm/imagination: Fit paired fragment job in the correct CCCB
CVE-2026-68438smp: Make CSD lock acquisition atomic for debug mode
CVE-2026-68450btrfs: free mapping node on duplicate reloc root insert
CVE-2026-68440net: txgbe: fix heap overflow when reading module EEPROM
CVE-2026-68441net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
CVE-2026-68442btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
CVE-2026-68443hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
CVE-2026-68444firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
CVE-2026-68445drm/vc4: Prevent shader BO mappings from becoming writable
CVE-2026-68446drm/vmwgfx: Validate vmw_surface_metadata::array_size
CVE-2026-68447drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size

Showing 20 of 22 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-68448へのコメント

まだコメントはありません


コメントを残す