7.8
CVE-2026-64074
- EPSS 0.13%
- Veröffentlicht 19.07.2026 15:39:49
- Zuletzt bearbeitet 30.07.2026 14:59:47
- CVE-Watchlists
- Unerledigt
fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap
In the Linux kernel, the following vulnerability has been resolved:
fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap
statmount_mnt_idmap() writes one mapping with seq_printf() and then
manually advances seq->count to include the NUL separator.
If seq_printf() overflows, seq_set_overflow() sets seq->count to
seq->size. The manual seq->count++ changes this to seq->size + 1.
seq_has_overflowed() then no longer detects the overflow. The corrupted
count returns to statmount_string(), which later executes:
seq->buf[seq->count++] = '\0';
This causes a 1-byte NULL out-of-bounds write on the dynamically
allocated seq buffer.
Fix this by checking for overflow immediately after seq_printf().Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
37c4a9590e1efcae7749682239fc22a330d2d325
Version <
e37ea2c6f17f273813ea4e8e94c102591d598ce1
Status
affected
Version
37c4a9590e1efcae7749682239fc22a330d2d325
Version <
93614949dc86f068e3c32c32cf1ee2a2323177a7
Status
affected
Version
37c4a9590e1efcae7749682239fc22a330d2d325
Version <
a3bf0f28d4ba16e1f35f8c983bb04426b87e2a78
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.15
Status
affected
Version
0
Version <
6.15
Status
unaffected
Version <=
6.18.*
Version
6.18.34
Status
unaffected
Version <=
7.0.*
Version
7.0.11
Status
unaffected
Version <=
*
Version
7.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.027 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/e37ea2c6f17f273813ea4e8e94c102591d598ce1
https://git.kernel.org/stable/c/93614949dc86f068e3c32c32cf1ee2a2323177a7
https://git.kernel.org/stable/c/a3bf0f28d4ba16e1f35f8c983bb04426b87e2a78