-

CVE-2026-64544

crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents

In the Linux kernel, the following vulnerability has been resolved:

crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents

pefile_digest_pe_contents() computes the trailing-data hash length as
pelen - (hashed_bytes + certs_size). A crafted PE can make the addition
exceed pelen, causing the unsigned subtraction to underflow to ~4 GiB.
This is passed to crypto_shash_update() which reads out of bounds and
panics on unmapped vmalloc guard pages.

 BUG: unable to handle page fault for address: ffffc900038d8000
 Oops: Oops: 0000 [#1] SMP KASAN NOPTI
 RIP: 0010:sha256_blocks_generic (lib/crypto/sha256.c:152)
 Call Trace:
  <TASK>
  __sha256_update (lib/crypto/sha256.c:208)
  crypto_sha256_update (crypto/sha256.c:142)
  verify_pefile_signature (crypto/asymmetric_keys/verify_pefile.c:436)
  kexec_kernel_verify_pe_sig (kernel/kexec_file.c:151)
  __do_sys_kexec_file_load (kernel/kexec_file.c:406)
  do_syscall_64 (arch/x86/entry/syscall_64.c:94)
  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
  </TASK>
 Kernel panic - not syncing: Fatal exception

Validate that the addition does not overflow and the result does not
exceed pelen before the subtraction. Return -ELIBBAD on failure.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version af316fc442ef23901bbfcec5af55e69ca6ce9563
Version < 89efd998470a93284b7ad5a20d4e0e3c6858ae8e
Status affected
Version af316fc442ef23901bbfcec5af55e69ca6ce9563
Version < 7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c
Status affected
Version af316fc442ef23901bbfcec5af55e69ca6ce9563
Version < b798ada5a5d1cb4cc4cfa72074b1b463eca6c506
Status affected
Version af316fc442ef23901bbfcec5af55e69ca6ce9563
Version < 627938383761fb4334b41ebe7ef438d6b8b19d60
Status affected
Version af316fc442ef23901bbfcec5af55e69ca6ce9563
Version < e162bc386e71b5412425a38ee048e8d2185491b9
Status affected
Version af316fc442ef23901bbfcec5af55e69ca6ce9563
Version < 6acd2fbd00f9c72aebefce63fc2e73e8f3d79061
Status affected
Version af316fc442ef23901bbfcec5af55e69ca6ce9563
Version < 803591785d33cf13b6f73ce2796e8b9e6d5e6526
Status affected
Version af316fc442ef23901bbfcec5af55e69ca6ce9563
Version < f7dd32c5179d7755de18e21d5674b08f9e5cb180
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.17
Status affected
Version 0
Version < 3.17
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/89efd998470a93284b7ad5a20d4e0e3c6858ae8e
https://git.kernel.org/stable/c/7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c
https://git.kernel.org/stable/c/b798ada5a5d1cb4cc4cfa72074b1b463eca6c506
https://git.kernel.org/stable/c/627938383761fb4334b41ebe7ef438d6b8b19d60
https://git.kernel.org/stable/c/e162bc386e71b5412425a38ee048e8d2185491b9
https://git.kernel.org/stable/c/6acd2fbd00f9c72aebefce63fc2e73e8f3d79061
https://git.kernel.org/stable/c/803591785d33cf13b6f73ce2796e8b9e6d5e6526
https://git.kernel.org/stable/c/f7dd32c5179d7755de18e21d5674b08f9e5cb180