diff --git a/core/modules/comment/comment.module b/core/modules/comment/comment.module
index 0a7b261..464ede5 100644
--- a/core/modules/comment/comment.module
+++ b/core/modules/comment/comment.module
@@ -10,6 +10,7 @@
  */
 
 use Drupal\node\Node;
+use Drupal\Core\File\File;
 use Symfony\Component\HttpFoundation\Request;
 use Symfony\Component\HttpKernel\Exception\NotFoundHttpException;
 use Symfony\Component\HttpKernel\HttpKernelInterface;
@@ -2515,7 +2516,7 @@ function comment_rdf_mapping() {
 /**
  * Implements hook_file_download_access().
  */
-function comment_file_download_access($field, $entity_type, $entity) {
+function comment_file_download_access($field, $entity_type, $entity, File $file) {
   if ($entity_type == 'comment') {
     if (user_access('access comments') && $entity->status == COMMENT_PUBLISHED || user_access('administer comments')) {
       $node = node_load($entity->nid);
diff --git a/core/modules/file/file.api.php b/core/modules/file/file.api.php
index 7f20d83..76a1856 100644
--- a/core/modules/file/file.api.php
+++ b/core/modules/file/file.api.php
@@ -18,6 +18,8 @@
  *   The type of $entity; for example, 'node' or 'user'.
  * @param $entity
  *   The $entity to which $file is referenced.
+ * @param Drupal\Core\File\File $file
+ *   The file entity that is being requested.
  *
  * @return
  *   TRUE is access should be allowed by this entity or FALSE if denied. Note
@@ -26,7 +28,7 @@
  *
  * @see hook_field_access().
  */
-function hook_file_download_access($field, $entity_type, $entity) {
+function hook_file_download_access($field, $entity_type, $entity, Drupal\Core\File\File $file) {
   if ($entity_type == 'node') {
     return node_access('view', $entity);
   }
@@ -45,20 +47,22 @@ function hook_file_download_access($field, $entity_type, $entity) {
  *   An array of grants gathered by hook_file_download_access(). The array is
  *   keyed by the module that defines the entity type's access control; the
  *   values are Boolean grant responses for each module.
- * @param $field
- *   The field to which the file belongs.
- * @param $entity_type
- *   The type of $entity; for example, 'node' or 'user'.
- * @param $entity
- *   The $entity to which $file is referenced.
+ * @param array $context
+ *   An associative array containing the following key-value pairs:
+ *   - entity_type: The type of entity; for example, node or user.
+ *   - entity: The entity to which the field item is referenced.
+ *   - field: The field info of the field the field_item belongs to.
+ *   - file: The file entity that is being requested.
  *
  * @return
  *   An array of grants, keyed by module name, each with a Boolean grant value.
  *   Return an empty array to assert FALSE. You may choose to return your own
  *   module's value in addition to other grants or to overwrite the values set
  *   by other modules.
+ *
+ * @see hook_file_download_access().
  */
-function hook_file_download_access_alter(&$grants, $field, $entity_type, $entity) {
+function hook_file_download_access_alter(&$grants, $context) {
   // For our example module, we always enforce the rules set by node module.
   if (isset($grants['node'])) {
     $grants = array('node' => $grants['node']);
diff --git a/core/modules/file/file.module b/core/modules/file/file.module
index 24dd94f..d280693 100644
--- a/core/modules/file/file.module
+++ b/core/modules/file/file.module
@@ -167,24 +167,28 @@ function file_file_download($uri, $field_type = 'file') {
       foreach ($type_references as $id => $reference) {
         // Try to load $entity and $field.
         $entity = entity_load($entity_type, $id);
-        $field = NULL;
+        $field = field_info_field($field_name);
+
+        // Load the field item that references the file.
+        $match = FALSE;
         if ($entity) {
-          // Load all fields for that entity.
+          // Load all fields items for that entity.
           $field_items = field_get_items($entity_type, $entity, $field_name);
 
-          // Find the field item with the matching URI.
-          foreach ($field_items as $field_item) {
-            if (file_load($field_item['fid'])->uri == $uri) {
-              $field = field_info_field($field_name);
+          // Try to find the field item that references the given file.
+          foreach ($field_items as $item) {
+            if ($file->fid == $item['fid']) {
+              $match = TRUE;
               break;
             }
           }
         }
 
-        // Check that $entity and $field were loaded successfully and check if
-        // access to that field is not disallowed. If any of these checks fail,
-        // stop checking access for this reference.
-        if (empty($entity) || empty($field) || !field_access('view', $field, $entity_type, $entity)) {
+        // Check that $entity and $field were loaded successfully, a field
+        // item that references the file exists and check if access to that
+        // field is not disallowed. If any of these checks fail, stop checking
+        // access for this reference.
+        if (empty($entity) || empty($field) || !$match || !field_access('view', $field, $entity_type, $entity)) {
           $denied = TRUE;
           break;
         }
@@ -193,10 +197,16 @@ function file_file_download($uri, $field_type = 'file') {
         // Default to FALSE and let entities overrule this ruling.
         $grants = array('system' => FALSE);
         foreach (module_implements('file_download_access') as $module) {
-          $grants = array_merge($grants, array($module => module_invoke($module, 'file_download_access', $field, $entity_type, $entity)));
+          $grants = array_merge($grants, array($module => module_invoke($module, 'file_download_access', $field, $entity_type, $entity, $file)));
         }
         // Allow other modules to alter the returned grants/denies.
-        drupal_alter('file_download_access', $grants, $field, $entity_type, $entity);
+        $context = array(
+          'entity_type' => $entity_type,
+          'entity' => $entity,
+          'field' => $field,
+          'file' => $file,
+        );
+        drupal_alter('file_download_access', $grants, $context);
 
         if (in_array(TRUE, $grants)) {
           // If TRUE is returned, access is granted and no further checks are
diff --git a/core/modules/file/lib/Drupal/file/Tests/FilePrivateTest.php b/core/modules/file/lib/Drupal/file/Tests/FilePrivateTest.php
index 2522da6..7d5f8ae 100644
--- a/core/modules/file/lib/Drupal/file/Tests/FilePrivateTest.php
+++ b/core/modules/file/lib/Drupal/file/Tests/FilePrivateTest.php
@@ -20,7 +20,7 @@ class FilePrivateTest extends FileFieldTestBase {
   }
 
   function setUp() {
-    parent::setUp('node_access_test');
+    parent::setUp('node_access_test', 'field_test');
     node_access_rebuild();
     variable_set('node_access_test_private', TRUE);
   }
@@ -37,6 +37,10 @@ class FilePrivateTest extends FileFieldTestBase {
     $field_name = strtolower($this->randomName());
     $this->createFileField($field_name, $type_name, array('uri_scheme' => 'private'));
 
+    // Create a field with no view access - see field_test_field_access().
+    $no_access_field_name = 'field_no_view_access';
+    $this->createFileField($no_access_field_name, $type_name, array('uri_scheme' => 'private'));
+
     $test_file = $this->getTestFile('text');
     $nid = $this->uploadNodeFile($test_file, $field_name, $type_name, TRUE, array('private' => TRUE));
     $node = node_load($nid, NULL, TRUE);
@@ -47,5 +51,14 @@ class FilePrivateTest extends FileFieldTestBase {
     $this->drupalLogOut();
     $this->drupalGet(file_create_url($node_file->uri));
     $this->assertResponse(403, t('Confirmed that access is denied for the file without the needed permission.'));
+
+    // Test with the field that should deny access through field access.
+    $this->drupalLogin($this->admin_user);
+    $nid = $this->uploadNodeFile($test_file, $no_access_field_name, $type_name, TRUE, array('private' => TRUE));
+    $node = node_load($nid, NULL, TRUE);
+    $node_file = file_load($node->{$no_access_field_name}[LANGUAGE_NOT_SPECIFIED][0]['fid']);
+    // Ensure the file cannot be downloaded.
+    $this->drupalGet(file_create_url($node_file->uri));
+    $this->assertResponse(403, t('Confirmed that access is denied for the file without view field access permission.'));
   }
 }
diff --git a/core/modules/file/tests/file_module_test.module b/core/modules/file/tests/file_module_test.module
index 490ef42..46b36bf 100644
--- a/core/modules/file/tests/file_module_test.module
+++ b/core/modules/file/tests/file_module_test.module
@@ -72,7 +72,7 @@ function file_module_test_form_submit($form, &$form_state) {
 /**
  * Implements hook_file_download_access().
  */
-function file_module_test_file_download_access($field, $entity_type, $entity) {
+function file_module_test_file_download_access($field, $entity_type, $entity, $field_item) {
   list(,, $bundle) = entity_extract_ids($entity_type, $entity);
   $instance = field_info_instance($entity_type, $field['field_name'], $bundle);
   // Allow the file to be downloaded only if the given arguments are correct.
diff --git a/core/modules/node/node.module b/core/modules/node/node.module
index d4bd4a4..7c1bd25 100644
--- a/core/modules/node/node.module
+++ b/core/modules/node/node.module
@@ -14,6 +14,7 @@ use Drupal\Core\Database\Query\AlterableInterface;
 use Drupal\Core\Database\Query\SelectExtender;
 use Drupal\Core\Database\Query\SelectInterface;
 use Drupal\node\Node;
+use Drupal\Core\File\File;
 
 /**
  * Denotes that the node is not published.
@@ -4047,7 +4048,7 @@ function node_modules_disabled($modules) {
 /**
  * Implements hook_file_download_access().
  */
-function node_file_download_access($field, $entity_type, $entity) {
+function node_file_download_access($field, $entity_type, $entity, File $file) {
   if ($entity_type == 'node') {
     return node_access('view', $entity);
   }
diff --git a/core/modules/user/user.module b/core/modules/user/user.module
index 53b993f..9f00cd1 100644
--- a/core/modules/user/user.module
+++ b/core/modules/user/user.module
@@ -3735,7 +3735,7 @@ function user_rdf_mapping() {
 /**
  * Implements hook_file_download_access().
  */
-function user_file_download_access($field, $entity_type, $entity) {
+function user_file_download_access($field, $entity_type, $entity, File $file) {
   if ($entity_type == 'user') {
     return user_view_access($entity);
   }
