Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-68448— ovl: check access to copy_file_range source with src mounter creds

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 5.3版本存在安全漏洞,该漏洞源于overlayfs在执行copy_file_range操作时,对源文件的读取权限检查使用了错误的挂载凭据,可能导致拒绝访问或允许读取未授权文件。

AI Predicted 4.7 Difficulty: Moderate EPSS 0.15% · P5

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux 5dae222a5ff0c269730393018a5539cc970a4726< 9ec22c8113d8cf72ed7197bb61037dcad09e50d8 affected
5dae222a5ff0c269730393018a5539cc970a4726< 1f4a107439d2e43db176e34919933e617cb7f2c5 affected
5dae222a5ff0c269730393018a5539cc970a4726< a1e0eb8f55cfe09bb31a202a388babc411292656 affected
5.3 affected
< 5.3 unaffected
6.18.42≤ 6.18.* unaffected
7.1.6≤ 7.1.* unaffected
7.2≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-68448

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ovl: check access to copy_file_range source with src mounter creds
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_file_range source with src mounter creds Commit 5dae222a5ff0c ("vfs: allow copy_file_range to copy across devices") allowed filesystems that implement the copy_file_range() f_op to decide if they want to access cross-sb copy from/to the same fs type. The same commit added checks to verify same sb copy for filesystems that implement ->copy_file_range() and do not support cross-sb copy at the time, namely, to ceph, fuse and nfs. The two remaining fs which implement ->copy_file_range(), cifs and overlayfs started to support cross-sb copy from this time. While overlayfs does support cross-sb copy when the two underlying files are on the same base fs, the copy operation on the two real files from two different overalyfs filesystems is performed with the mounter creds of the destination overlayfs and the read permission access hook for the source file was called with the wrong creds. This could cause either deny of access to copy which would otherwise be allowed (e.g. with splice) or allow read access to file which would otherwise be denied. Fix the latter case by explicitly verifying read access to source file with the source overlayfs mounter creds. The former case remains a quirk of cross-sb overlayfs copy, but userspace could fall back to regular copy so no harm done.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 5.3版本存在安全漏洞,该漏洞源于overlayfs在执行copy_file_range操作时,对源文件的读取权限检查使用了错误的挂载凭据,可能导致拒绝访问或允许读取未授权文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 5dae222a5ff0c269730393018a5539cc970a4726 ~ 9ec22c8113d8cf72ed7197bb61037dcad09e50d8 -
Linux Linux 5.3 -

II. Public POCs for CVE-2026-68448

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-68448

登录查看更多情报信息。

Patches & Fixes for CVE-2026-68448 (3)

Same Patch Batch · Linux · 2026-08-12 · 22 CVEs total

CVE-2026-68431 9.1 CRITICAL ksmbd: validate minimum PDU size for transform requests
CVE-2026-68432 8.8 HIGH vxlan: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-68433 8.6 HIGH libceph: bound get_version reply decode to front len
CVE-2026-68446 7.8 HIGH drm/vmwgfx: Validate vmw_surface_metadata::array_size
CVE-2026-68445 7.8 HIGH drm/vc4: Prevent shader BO mappings from becoming writable
CVE-2026-68440 7.8 HIGH net: txgbe: fix heap overflow when reading module EEPROM
CVE-2026-68442 7.8 HIGH btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
CVE-2026-68447 7.1 HIGH drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size
CVE-2026-68439 wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
CVE-2026-68450 btrfs: free mapping node on duplicate reloc root insert
CVE-2026-68449 ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
CVE-2026-68444 firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
CVE-2026-68443 hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
CVE-2026-68441 net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
CVE-2026-68429 drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
CVE-2026-68438 smp: Make CSD lock acquisition atomic for debug mode
CVE-2026-68437 drm/imagination: Fit paired fragment job in the correct CCCB
CVE-2026-68436 drm/amd/display: use kvzalloc to allocate struct dc
CVE-2026-68435 LoongArch: Fix address space mismatch in kexec command line lookup
CVE-2026-68434 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms

Showing top 20 of 22 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-68448

No comments yet


Leave a comment