-

CVE-2026-93828

exfat: fix handling of damaged volume in exfat_create_upcase_table()

In the Linux kernel, the following vulnerability has been resolved:

exfat: fix handling of damaged volume in exfat_create_upcase_table()

When the size of the upcase table is set to zero in the dentry for any
reason(e.g. corrupted media or misbehaving device), an integer overflow
causes the module to loop indefinitely.

If the size of the upcase table is read zero, do not attempt to load the
table. Instead, fallback to loading the default upcase table. If the
size of the upcase table is zero or no upcase table is found, raise
exfat_fs_error() to mark the volume read-only.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 370e812b3ec190fa492c9fd5a80c38b086d105c0
Version < 60ace93811609e4dd883e9de5fb4462ed834160a
Status affected
Version 370e812b3ec190fa492c9fd5a80c38b086d105c0
Version < 2cc0b612343638057ef321ce735201a7c2f52f25
Status affected
Version 370e812b3ec190fa492c9fd5a80c38b086d105c0
Version < 20dd3185d13865214ff25b0bf7b931e8d73be1ac
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/60ace93811609e4dd883e9de5fb4462ed834160a
https://git.kernel.org/stable/c/2cc0b612343638057ef321ce735201a7c2f52f25
https://git.kernel.org/stable/c/20dd3185d13865214ff25b0bf7b931e8d73be1ac