7.8
CVE-2026-64324
- EPSS 0.16%
- Veröffentlicht 25.07.2026 08:49:52
- Zuletzt bearbeitet 17.08.2026 05:17:33
- CVE-Watchlists
- Unerledigt
udf: validate free block extents against the partition length
In the Linux kernel, the following vulnerability has been resolved: udf: validate free block extents against the partition length udf_free_blocks() checks the logical block number and count against the partition length, but drops the extent offset from that final bound. A crafted extent can pass the guard while logicalBlockNum + offset + count points past the partition, which later indexes past the space bitmap array. A single ftruncate(2) on a file backed by such an extent reliably panics the kernel. This is a local availability issue. On desktop systems where UDisks/polkit allows the active user to mount removable UDF media without CAP_SYS_ADMIN, an unprivileged local user can supply the crafted filesystem and trigger the panic by truncating a writable file on it. Systems that require root or CAP_SYS_ADMIN to mount the image have a higher prerequisite. No confidentiality or integrity impact is claimed: the reproduced primitive is an out-of-bounds read of a bitmap pointer slot followed by a kernel panic. Use the already computed logicalBlockNum + offset + count value for the partition length check. Also make load_block_bitmap() reject an out-of-range block group before indexing s_block_bitmap[], so corrupted callers cannot walk past the flexible array.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
934f815345c09c290a9b9a9cfdddc203ec2117e8
Version <
fdd6229d2ae9914c1f25d1041db0f4f312a4fa76
Status
affected
Version
22cc7323f090646c8cfb5939e6f15bdc2ed3fd27
Version <
b54aee5652fcd7c23a0904a4623ec462c3edc70c
Status
affected
Version
7c4fa9ebfce69619d132fe703dc2e2cf62a13723
Version <
12af328d2ee8d68e81ba612246d0b54b22d23e1f
Status
affected
Version
5cc9745e2ea11aef7d5c9a42bc36f6cd3e1b4cc3
Version <
fb49099206c5c57af28a157249fa7bcb5518f99e
Status
affected
Version
56e69e59751d20993f243fb7dd6991c4e522424c
Version <
9442d75429b0c556292a7454fe888d54259f5240
Status
affected
Version
56e69e59751d20993f243fb7dd6991c4e522424c
Version <
335202ab25b01fdd45889ff25eab70864686dea3
Status
affected
Version
56e69e59751d20993f243fb7dd6991c4e522424c
Version <
be87de7789a82a030a4896bc7683415ec9fa6f2b
Status
affected
Version
56e69e59751d20993f243fb7dd6991c4e522424c
Version <
5f0419457f89dce1a3f1c8e62a3adf2f39ab8168
Status
affected
Version
097420e48e30f51e8f4f650b5c946f5af63ec1a3
Status
affected
Version
5def895b42ef16a2da6402818cba8d7ec8ede1ef
Status
affected
Version
05fb2bf477d3fe5421bd4cb699574737f52bd88b
Status
affected
Version
5.10.224
Version <
5.10.261
Status
affected
Version
5.15.165
Version <
5.15.212
Status
affected
Version
6.1.105
Version <
6.1.178
Status
affected
Version
6.6.46
Version <
6.6.145
Status
affected
Version
4.19.320
Version <
4.20
Status
affected
Version
5.4.282
Version <
5.5
Status
affected
Version
6.10.5
Version <
6.11
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.11
Status
affected
Version
0
Version <
6.11
Status
unaffected
Version <=
5.10.*
Version
5.10.261
Status
unaffected
Version <=
5.15.*
Version
5.15.212
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.96
Status
unaffected
Version <=
6.18.*
Version
6.18.39
Status
unaffected
Version <=
7.1.*
Version
7.1.4
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.052 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/fdd6229d2ae9914c1f25d1041db0f4f312a4fa76
https://git.kernel.org/stable/c/b54aee5652fcd7c23a0904a4623ec462c3edc70c
https://git.kernel.org/stable/c/12af328d2ee8d68e81ba612246d0b54b22d23e1f
https://git.kernel.org/stable/c/fb49099206c5c57af28a157249fa7bcb5518f99e
https://git.kernel.org/stable/c/9442d75429b0c556292a7454fe888d54259f5240
https://git.kernel.org/stable/c/335202ab25b01fdd45889ff25eab70864686dea3
https://git.kernel.org/stable/c/be87de7789a82a030a4896bc7683415ec9fa6f2b
https://git.kernel.org/stable/c/5f0419457f89dce1a3f1c8e62a3adf2f39ab8168