7.8

CVE-2026-64322

udf: validate sparing table length as an entry count, not a byte count

In the Linux kernel, the following vulnerability has been resolved:

udf: validate sparing table length as an entry count, not a byte count

udf_load_sparable_map() accepts a sparing table when

	sizeof(*st) + le16_to_cpu(st->reallocationTableLen) > sb->s_blocksize

is false, i.e. it treats reallocationTableLen as a number of BYTES that
must fit in the block.  But the table is walked as an array of 8-byte
sparingEntry elements:

	for (i = 0; i < le16_to_cpu(st->reallocationTableLen); i++) {
		struct sparingEntry *entry = &st->mapEntry[i];
		... entry->origLocation ...
	}

in udf_get_pblock_spar15() and udf_relocate_blocks().  A
reallocationTableLen of N therefore passes the check whenever
sizeof(*st) + N <= blocksize, yet the consumers index
sizeof(*st) + N * sizeof(struct sparingEntry) bytes -- up to ~8x the
block.  On a crafted UDF image this is an out-of-bounds read in
udf_get_pblock_spar15(); udf_relocate_blocks() additionally feeds the
same length to udf_update_tag(), whose crc_itu_t() reads far past the
block, and its memmove() through st->mapEntry[] is an out-of-bounds
write.

Validate reallocationTableLen as the entry count it is, with
struct_size().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 1df2ae31c724e57be9d7ac00d78db8a5dabdd050
Version < eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e
Status affected
Version 1df2ae31c724e57be9d7ac00d78db8a5dabdd050
Version < 0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9
Status affected
Version 1df2ae31c724e57be9d7ac00d78db8a5dabdd050
Version < 2d726135099313958f8975532a2e15322ff150ce
Status affected
Version 1df2ae31c724e57be9d7ac00d78db8a5dabdd050
Version < 7285276aa50d2839afb5957ffd491ad282dc8f72
Status affected
Version 1df2ae31c724e57be9d7ac00d78db8a5dabdd050
Version < 2a219acb2ce674d99bbd1b7b35ed8c384dac7200
Status affected
Version 1df2ae31c724e57be9d7ac00d78db8a5dabdd050
Version < 04f4599a9efb90992d072a814960edf0cd62805d
Status affected
Version 1df2ae31c724e57be9d7ac00d78db8a5dabdd050
Version < 7f7774b9da0ef17b87bfa238cf966ad0b3376150
Status affected
Version 1df2ae31c724e57be9d7ac00d78db8a5dabdd050
Version < 3ec997bd5508e9b25210b5bbec89031629cdb093
Status affected
Version e240873cb4a9fd18de60a817100a96fe670d4359
Status affected
Version 9ae30e324a96d0328a575329d7a95a09b3318601
Status affected
Version b1c5701ad6b3e5d21d16f65475651cfaaa41e7aa
Status affected
Version a9f1af04f086656246f30354fb4564ce3b08c4a0
Status affected
Version 4836ee563d65bb492f907cbe267a5761b9693e4d
Status affected
Version 2.6.32.60
Version < 2.6.33
Status affected
Version 2.6.34.14
Version < 2.6.35
Status affected
Version 3.0.37
Version < 3.1
Status affected
Version 3.2.23
Version < 3.3
Status affected
Version 3.4.5
Version < 3.5
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.5
Status affected
Version 0
Version < 3.5
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.06
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e
https://git.kernel.org/stable/c/0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9
https://git.kernel.org/stable/c/2d726135099313958f8975532a2e15322ff150ce
https://git.kernel.org/stable/c/7285276aa50d2839afb5957ffd491ad282dc8f72
https://git.kernel.org/stable/c/2a219acb2ce674d99bbd1b7b35ed8c384dac7200
https://git.kernel.org/stable/c/04f4599a9efb90992d072a814960edf0cd62805d
https://git.kernel.org/stable/c/7f7774b9da0ef17b87bfa238cf966ad0b3376150
https://git.kernel.org/stable/c/3ec997bd5508e9b25210b5bbec89031629cdb093