{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-63808","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.013Z","datePublished":"2026-07-19T12:02:11.323Z","dateUpdated":"2026-08-17T04:51:14.402Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:51:14.402Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix potential use-after-free in exfat_find_dir_entry()\n\nIn exfat_find_dir_entry(), the buffer_head obtained from\nexfat_get_dentry() is released with brelse(bh) before the fall-through\nTYPE_EXTEND branch reads the directory entry through ep (which points\ninto bh->b_data):\n\n\tbrelse(bh);\n\tif (entry_type == TYPE_EXTEND) {\n\t\t...\n\t\tlen = exfat_extract_uni_name(ep, entry_uniname);\n\t\t...\n\t}\n\nAfter brelse() drops our reference, nothing guarantees that the\nunderlying page backing bh->b_data remains valid for the subsequent\nexfat_extract_uni_name() read. This is the same pattern fixed in\ncommit fc961522ddbd (\"exfat: Fix potential use after free in\nexfat_load_upcase_table()\").\n\nMove brelse(bh) so it runs after ep is no longer dereferenced on\neach branch.\n\nConfirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y\n+ CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image\n(long filename with same-hash collisions forcing the TYPE_EXTEND path).\nWith a debug-only invalidate_bdev() inserted between brelse(bh) and\nthe ep read to make the stale-deref window deterministic, the\nunpatched kernel faults:\n\n  BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0\n  BUG: unable to handle page fault for address: ffff88801a5fa0c2\n  Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI\n  RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0\n\nWith this patch applied, the same instrumented harness completes\ncleanly under the same sanitizer stack. I have not reproduced a\ncrash on an uninstrumented kernel under ordinary reclaim; the\ninstrumented A/B establishes the lifetime violation and that the\npatch closes it, not an unaided triggerability claim."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - exfat_find_dir_entry() is invoked during VFS directory lookups on mounted exFAT volumes, reachable remotely when that volume is exported via ksmbd or nfsd (common on NAS/router USB shares). A network client resolving paths on the share triggers server-side exfat_lookup without local shell access.\nAC:L - The attacker fully controls the crafted exFAT image to force the TYPE_EXTEND code path and can repeatedly trigger lookups (including concurrent SMB/NFS requests and memory pressure) to win the post-brelse buffer reclaim window. UAF lifetime violations are treated as low complexity per kernel guidance.\nPR:N - Exploitation requires only access to the mounted exFAT filesystem, not real root; guest/anonymous SMB shares on consumer NAS devices and auto-mounted removable media grant unprivileged attackers filesystem access without elevated kernel credentials.\nUI:N - Once a crafted exFAT image is present on a shared or auto-mounted volume, triggering the bug requires only automated path lookups (SMB OPEN/LOOKUP, openat, statx) with no additional victim interaction beyond normal filesystem access.\nS:U - Successful exploitation compromises kernel memory within the same security authority; this is a standard kernel memory corruption issue, not a cross-boundary escape such as VM guest-to-host breakout.\nC:H - The UAF reads freed buffer_head page cache memory through exfat_extract_uni_name(), enabling out-of-bounds kernel heap reads and information disclosure from attacker-influenced reclaimed data.\nI:H - Use-after-free on buffer_head data provides a foundation for heap grooming and arbitrary memory corruption primitives that can be leveraged for kernel code execution and integrity compromise.\nA:H - The bug is a confirmed kernel use-after-free that produced a KASAN fault and page fault oops; even without full exploitation it can cause kernel crashes and denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/exfat/dir.c"],"versions":[{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"e6f1a11cfb808441a43ffae9b476cc135732cd27","status":"affected","versionType":"git"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"e48f413c2815787b8cade2795e194e3c4cd782ef","status":"affected","versionType":"git"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"06c4e1e9967d332ac33ba38b7819851089ff9359","status":"affected","versionType":"git"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"8e0abc17fbd7e305802e84fe98b4950d50f9c433","status":"affected","versionType":"git"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"4d101016d5e587f820b3ae2d5bb6770d86342649","status":"affected","versionType":"git"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"adfacfbaeae2cb760f492357cc36b41f84ef7f86","status":"affected","versionType":"git"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"708b97e792945d3e4653939fd3405d71a61ad065","status":"affected","versionType":"git"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"3f5f8ee9917cc2b9076ac533492d8a200edcabb8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/exfat/dir.c"],"versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","status":"unaffected","versionType":"semver"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"5.10.260"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"5.15.211"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.1.177"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.6.144"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.12.95"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.18.38"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"7.1.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e6f1a11cfb808441a43ffae9b476cc135732cd27"},{"url":"https://git.kernel.org/stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef"},{"url":"https://git.kernel.org/stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359"},{"url":"https://git.kernel.org/stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433"},{"url":"https://git.kernel.org/stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649"},{"url":"https://git.kernel.org/stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86"},{"url":"https://git.kernel.org/stable/c/708b97e792945d3e4653939fd3405d71a61ad065"},{"url":"https://git.kernel.org/stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8"}],"title":"exfat: fix potential use-after-free in exfat_find_dir_entry()","x_generator":{"engine":"bippy-1.2.0"}}}}