Red Hat Linux Security Advisories & CVEs
4701 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-19484] Denial of Service via oversized multipart boundary
@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry byte array, and a boundary of exactly 252 bytes makes the search needle 256 bytes, which truncates the default skip distance to zero and turns the search into a CPU bound loop on a small body. A single small request can keep one core busy and deny service to other requests handled by the same process. The issue is fixed in @fastify/busboy 3.2.1, which widens the skip table so the skip distance is preserved. Users should upgrade to 3.2.1. This can cause the Node.js event loop to stall, leading to a CPU-bound loop that consumes significant processing resources. Red Hat products that include @fastify/busboy are not affected by this vulnerability. CVE-2026-19484 is present only in @fastify/busboy versions 3.1.0 through 3.2.0. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606. Red Hat lists OpenShift Pipelines; Red Hat AMQ Broker 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4 as not affected.
High [CVE-2026-19481] Denial of Service from crafted form-data headers
@fastify/busboy is a multipart form-data parser. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1. A remote attacker can exploit this vulnerability by sending specially crafted multipart form-data headers. This can cause a TypeError in the parser, leading to the termination of the Node.js process and resulting in an unauthenticated Denial of Service (DoS). The unauthenticated nature and potential for service disruption elevate the impact to Important. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-915. Affected Red Hat products: OpenShift Pipelines; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat AMQ Broker 7; Red Hat OpenShift Container Platform 4 as not affected. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-67986] Arbitrary code execution via Ruby code injection in AwesomeMethodArray#grep
amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names. A flaw was found in amazing_print. This vulnerability allows an attacker to inject and execute arbitrary Ruby code within the host process. Red Hat Satellite includes the rubygem-amazing_print package as a dependency of the hammer CLI tool. While the vulnerable code exists in the shipped version, the specific code path that enables exploitation — calling grep with a block on method arrays — is not used by Satellite or any of its components. The gem is used solely for debug-level object formatting. As a result, this vulnerability is not exploitable in Red Hat Satellite as shipped. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-94. Red Hat lists Red Hat Satellite 6 as not affected.
High [CVE-2026-68453] Fix buffer over-read in cca_cipher2protkey
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read. So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of sizeof key token struct... key buf length This vulnerability arises from insufficient validation of user-controlled length fields within the Common Cryptographic Architecture (CCA) token structures. This could lead to a kernel crash, resulting in a denial of service, or the exposure of sensitive memory information.
High [CVE-2026-68452] Validate length for CCA AES cipher key requests
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block. A local attacker could exploit this by providing a specially crafted key token, which may lead to a buffer overflow. This could result in a denial of service, making the system unavailable. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68451] Validate length for CCA ECC private key requests
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block. The `cca_ecc2protkey()` function, responsible for handling Common Cryptographic Architecture (CCA) Elliptic Curve Cryptography (ECC) private key requests, does not properly validate the length of the key token. This allows a local attacker to provide a malformed key token, potentially leading to memory corruption and a denial of service. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-805. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-46382] Server-Side Request Forgery in import functionality
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known workarounds are available. This vulnerability, known as Server-Side Request Forgery (SSRF), allows a remote attacker to trick the server into making requests to internal or local network resources. By exploiting this, an attacker could potentially gain unauthorized access to sensitive information or perform actions on behalf of the server. This Important flaw in the Meeting Room Booking System (MRBS) import functionality allows a remote attacker to perform Server-Side Request Forgery (SSRF). This enables the server to fetch private or local network URIs without proper validation, potentially leading to unauthorized information disclosure or access to internal network services. The impact is elevated due to the potential for internal network reconnaissance and interaction. This component is shipped only in Fedora. Red Hat does not ship this component in any core Red Hat products. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-918.
High [CVE-2026-71469] Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This risk is heightened by the component's exposure to unauthenticated requests. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.
High [CVE-2026-71473] addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially compromising its integrity. Important: This flaw in Red Hat Advanced Cluster Management for Kubernetes allows a user with `patch managedclusteraddons` permission on a managed cluster to achieve container image injection. By manipulating the `addon.open-cluster-management.io/values` annotation on a `ManagedClusterAddOn`, an attacker can override Helm values, leading to privilege escalation and arbitrary code execution on the managed cluster. Red Hat severity: Important — CVSS 8.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N). Weakness: CWE-915. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more.
High [CVE-2026-73500] Denial of Service via unbounded TLS handshake goroutines
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls. Conn. Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1. A remote attacker can exploit this by opening numerous TCP connections to an etcd TLS listener without completing the TLS handshake. This action causes the `tlsListener.acceptLoop` to spawn an unbounded number of goroutines, which consume excessive memory. This resource exhaustion leads to a Denial of Service (DoS) for the etcd cluster and, consequently, for the Kubernetes control plane it supports. This is an Important denial of service flaw in etcd, a critical component for distributed systems and Kubernetes control planes. A remote attacker can exhaust etcd memory by initiating numerous incomplete TLS handshakes, leading to a loss of availability for affected clusters.
High [CVE-2026-19654] Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected. This vulnerability in rsyslog allows an unauthenticated peer to crash the rsyslogd deamon, resulting a a Denial-of-Service, by sending a crafted input sequence. This happens because the malicious input ends creating an invalid internal message length, which crashes the rsyslogd receiving the input. This vulnerability is only exploitable when the following conditions are met: * imptcp module is explicitly loaded * There's an imptcp listener using the non-default framing.delimiter.regex mode * The attacker is able to establish a TCP connection to the target listener Although this vulnerability has been rated as having an Important severity in upstream, the Red Hat Product Security team has rated it as having a MODERATE severity in supported Red Hat Products. This happens because the conditions described above are not met in default configurations of the `rsyslog` package as shipped with Red Hat Enterprise Linux Versions. Weakness: CWE-125.
High [CVE-2026-13622] virt-handler migration proxy follows symlinks allowing container escape to host
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc//root/ paths using net. Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise. Red Hat has rated this vulnerability as Important impact. The vulnerable code is in the virt-handler component, a privileged DaemonSet running as root in the host mount namespace on every compute node. Exploitation requires an authenticated user with namespace-level edit permissions (kubevirt.io:edit) and pods/exec access — standard permissions for VM operators. The impact of successful exploitation is complete node compromise via CRI-O socket access, bypassing all Kubernetes admission controls. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-22.
High [CVE-2026-73422] Arbitrary code execution via unescaped View Transition animation properties
Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an inline style element without escaping them for CSS and HTML contexts. An attacker-controlled View Transition animation value such as duration can terminate the generated style element and inject arbitrary HTML or JavaScript. The affected code is packages/astro/src/runtime/server/transition.ts; renderTransition passes sheet.toString() into markHTMLString(), while addAnimationProperty serializes duration through toTimeValue() and also handles easing, direction, delay, fillMode, and name. Exploitation requires an on-demand or server-rendered route to pass attacker-controlled data into a View Transition animation definition and can execute arbitrary JavaScript in the affected application's origin, allowing access to sensitive page data and authenticated actions available to the victim. This issue is fixed in version 7.1.0. A flaw was found in Astro. A remote attacker can exploit a reflected Cross-Site Scripting (XSS) vulnerability due to unescaped View Transition animation properties in the server-side CSS generator. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-73415] Arbitrary code execution via malicious image in image viewer
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image and revokes the blob URL too early, allowing the image to retain an executable same-origin context when it is opened through the image viewer and then opened in a new browser tab. The resulting cross-site scripting can be used to execute arbitrary code on the JupyterLab server. This issue is fixed in versions 4.5.10 and 4.6.2. A flaw was found in JupyterLab. This allows a remote attacker to exploit a cross-site scripting (XSS) vulnerability when a malicious image is opened through the image viewer and subsequently in a new browser tab. Successful exploitation could lead to arbitrary code execution on the JupyterLab server. Red Hat severity: Important — CVSS 8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-911. Affected Red Hat products: Red Hat OpenShift AI 2.25; Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI). Red Hat fixing advisory: RHSA-2026:65126.
High [CVE-2026-18724] Stack buffer overflow in idbm record parsing
AI_ONLY_REPORT package: iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10 ------ Summary: Stack Buffer Overflow in idbm_recinfo_config via Malicious iSCSI Target: a crafted SendTargets TargetName can inject an extra configuration line into a persisted node record and later cause a stack buffer overflow when that record is reparsed. Requirements to exploit: An attacker must control an iSCSI target or tamper with SendTargets discovery traffic, return a crafted `TargetName` containing a newline and oversized injected key or value data, have the victim run persistent discovery, and then trigger a later node-record read such as update or login. Component affected: `iscsi-initiator-utils`; `usr/idbm.c:idbm_recinfo_config`, with attacker-controlled input reaching it through SendTargets handling in `usr/discovery.c` and later record serialization in `usr/idbm.c`. Version affected: `iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10` Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H - 7.5 (HIGH) AV:N - The attacker can supply the malicious data over the network in a SendTargets discovery response. AC:L - The target-name length cap still leaves enough room for a newline plus an overlong injected key; no race or unusual memory state is required.
High [CVE-2026-73122] auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm repositories. This could lead to significant information disclosure. This broad access to critical data elevates the risk beyond a Moderate impact. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-269. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.
High [CVE-2026-66878] FetchChannelReferences honours Channel.spec.secretRef.namespace enabling cross-namespace Secret exfiltration
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel. Spec. SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure. This Important flaw in Red Hat Advanced Cluster Management allows a malicious namespace administrator to exfiltrate sensitive Secret data from other namespaces within the cluster. This impacts environments where untrusted namespace administrators have permissions to create Channel and Subscription resources. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-639. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.
High [CVE-2026-68432] require CAP_NET_ADMIN in the device netns for changelink
In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns vxlan->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in vxlan->net can rewrite a vxlan device whose underlay lives in vxlan->net. vxlan_changelink() validates and applies the new configuration against vxlan->net (vxlan_config_validate(vxlan->net,...)) and can reopen the underlay socket in that netns, so the same reasoning as the tunnel changelink series applies here. Gate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the "require CAP_NET_ADMIN in the device netns for changelink" series. Found by 0sec automated security-research tooling ( ). A flaw was found in the Linux kernel's VXLAN (Virtual Extensible LAN) implementation. A local attacker, with `CAP_NET_ADMIN` (network administration capability) in one network namespace, could exploit an incorrect privilege check in the `rtnl changelink` path.
High [CVE-2026-68442] don't propagate EXTENT_FLAG_LOGGING to split extent maps
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps When btrfs_drop_extent_map_range() splits an extent map, the new split maps inherit the original map's flags through a local 'flags' variable. Commit f86f7a75e2fb ("btrfs: use the flags of an extent map to identify the compression type") changed the EXTENT_FLAG_LOGGING clearing to operate on em->flags instead of that local 'flags' copy, so a split of an extent map that is currently being logged wrongly inherits EXTENT_FLAG_LOGGING. The flag is then never cleared on the split, and when it is freed while still on the inode's modified_extents list (for example by the extent map shrinker) it trips the WARN_ON(!list_empty(&em->list)) in btrfs_free_extent_map() and leads to a use-after-free. Clear EXTENT_FLAG_LOGGING from the local 'flags' copy used for the splits and only clear EXTENT_FLAG_PINNED from em->flags, restoring the behaviour prior to f86f7a75e2fb. A flaw was found in the btrfs filesystem component of the Linux kernel. This issue occurs because the flag clearing operation was applied to the wrong variable during the splitting process. Consequently, if a split extent map with this flag is freed while still in use, it can lead to a use-after-free vulnerability, potentially causing system instability or a denial of service.
High [CVE-2026-68448] check access to copy_file_range source with src mounter creds
In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_file_range source with src mounter creds Commit 5dae222a5ff0c ("vfs: allow copy_file_range to copy across devices") allowed filesystems that implement the copy_file_range() f_op to decide if they want to access cross-sb copy from/to the same fs type. The same commit added checks to verify same sb copy for filesystems that implement ->copy_file_range() and do not support cross-sb copy at the time, namely, to ceph, fuse and nfs. While overlayfs does support cross-sb copy when the two underlying files are on the same base fs, the copy operation on the two real files from two different overalyfs filesystems is performed with the mounter creds of the destination overlayfs and the read permission access hook for the source file was called with the wrong creds. This could cause either deny of access to copy which would otherwise be allowed (e.g. with splice) or allow read access to file which would otherwise be denied. The former case remains a quirk of cross-sb overlayfs copy, but userspace could fall back to regular copy so no harm done. A flaw was found in the Linux kernel's overlayfs component. When copying files across different overlay filesystems, the system incorrectly checked read permissions using the destination filesystem's credentials instead of the source's.