9.8

CVE-2026-63808

exfat: fix potential use-after-free in exfat_find_dir_entry()

In the Linux kernel, the following vulnerability has been resolved:

exfat: fix potential use-after-free in exfat_find_dir_entry()

In exfat_find_dir_entry(), the buffer_head obtained from
exfat_get_dentry() is released with brelse(bh) before the fall-through
TYPE_EXTEND branch reads the directory entry through ep (which points
into bh->b_data):

	brelse(bh);
	if (entry_type == TYPE_EXTEND) {
		...
		len = exfat_extract_uni_name(ep, entry_uniname);
		...
	}

After brelse() drops our reference, nothing guarantees that the
underlying page backing bh->b_data remains valid for the subsequent
exfat_extract_uni_name() read. This is the same pattern fixed in
commit fc961522ddbd ("exfat: Fix potential use after free in
exfat_load_upcase_table()").

Move brelse(bh) so it runs after ep is no longer dereferenced on
each branch.

Confirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y
+ CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image
(long filename with same-hash collisions forcing the TYPE_EXTEND path).
With a debug-only invalidate_bdev() inserted between brelse(bh) and
the ep read to make the stale-deref window deterministic, the
unpatched kernel faults:

  BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0
  BUG: unable to handle page fault for address: ffff88801a5fa0c2
  Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI
  RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0

With this patch applied, the same instrumented harness completes
cleanly under the same sanitizer stack. I have not reproduced a
crash on an uninstrumented kernel under ordinary reclaim; the
instrumented A/B establishes the lifetime violation and that the
patch closes it, not an unaided triggerability claim.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version ca06197382bde0a3bc20215595d1c9ce20c6e341
Version < e6f1a11cfb808441a43ffae9b476cc135732cd27
Status affected
Version ca06197382bde0a3bc20215595d1c9ce20c6e341
Version < e48f413c2815787b8cade2795e194e3c4cd782ef
Status affected
Version ca06197382bde0a3bc20215595d1c9ce20c6e341
Version < 06c4e1e9967d332ac33ba38b7819851089ff9359
Status affected
Version ca06197382bde0a3bc20215595d1c9ce20c6e341
Version < 8e0abc17fbd7e305802e84fe98b4950d50f9c433
Status affected
Version ca06197382bde0a3bc20215595d1c9ce20c6e341
Version < 4d101016d5e587f820b3ae2d5bb6770d86342649
Status affected
Version ca06197382bde0a3bc20215595d1c9ce20c6e341
Version < adfacfbaeae2cb760f492357cc36b41f84ef7f86
Status affected
Version ca06197382bde0a3bc20215595d1c9ce20c6e341
Version < 708b97e792945d3e4653939fd3405d71a61ad065
Status affected
Version ca06197382bde0a3bc20215595d1c9ce20c6e341
Version < 3f5f8ee9917cc2b9076ac533492d8a200edcabb8
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 5.10.*
Version 5.10.260
Status unaffected
Version <= 5.15.*
Version 5.15.211
Status unaffected
Version <= 6.1.*
Version 6.1.177
Status unaffected
Version <= 6.6.*
Version 6.6.144
Status unaffected
Version <= 6.12.*
Version 6.12.95
Status unaffected
Version <= 6.18.*
Version 6.18.38
Status unaffected
Version <= 7.1.*
Version 7.1.3
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.396
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e6f1a11cfb808441a43ffae9b476cc135732cd27
https://git.kernel.org/stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef
https://git.kernel.org/stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359
https://git.kernel.org/stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433
https://git.kernel.org/stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649
https://git.kernel.org/stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86
https://git.kernel.org/stable/c/708b97e792945d3e4653939fd3405d71a61ad065
https://git.kernel.org/stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8