Re: [PATCH stable/linux-5.10.y 0/7] Backport Fix incorrect overlayfs mmap() and mprotect() LSM access controls
Amir Goldstein <[email protected]> Tue, 30 Jun 2026 13:01:43 +0200
| Newsgroups | org.kernel.vger.linux-unionfs,org.kernel.vger.bpf,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-security-module,org.kernel.vger.selinux,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAOQ4uxh4-LYt8VUW5o+0mMrHpnZm3t8k4WD6x2kRqEj=_ZpLOA@mail.gmail.com> |
On Tue, Jun 30, 2026 at 5:06=E2=80=AFAM Cai Xinchen <[email protected]= > wrote: > > Thank you for your reply. Regarding the two points of feedback: > > First, 6.1 is still in the process of being adapted. So do not propose for 5.10 please. > > Second, this patch set is primarily intended to fix CVE-2026-46054, but > it seems that for lower versions to implement SELinux checks for overlay > mmap/mprotect checks, some dependencies are unavoidable. In such cases, > should we add more tests to reduce the risk and integrate the changes, > or should we simply not fix this issue? If more tests are needed, are > there any recommended test suites? I have concerns. The burdn of proof is on you. Thanks, Amir.