{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64322","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.780Z","datePublished":"2026-07-25T08:49:50.180Z","dateUpdated":"2026-08-17T04:53:23.900Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:53:23.900Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate sparing table length as an entry count, not a byte count\n\nudf_load_sparable_map() accepts a sparing table when\n\n\tsizeof(*st) + le16_to_cpu(st->reallocationTableLen) > sb->s_blocksize\n\nis false, i.e. it treats reallocationTableLen as a number of BYTES that\nmust fit in the block.  But the table is walked as an array of 8-byte\nsparingEntry elements:\n\n\tfor (i = 0; i < le16_to_cpu(st->reallocationTableLen); i++) {\n\t\tstruct sparingEntry *entry = &st->mapEntry[i];\n\t\t... entry->origLocation ...\n\t}\n\nin udf_get_pblock_spar15() and udf_relocate_blocks().  A\nreallocationTableLen of N therefore passes the check whenever\nsizeof(*st) + N <= blocksize, yet the consumers index\nsizeof(*st) + N * sizeof(struct sparingEntry) bytes -- up to ~8x the\nblock.  On a crafted UDF image this is an out-of-bounds read in\nudf_get_pblock_spar15(); udf_relocate_blocks() additionally feeds the\nsame length to udf_update_tag(), whose crc_itu_t() reads far past the\nblock, and its memmove() through st->mapEntry[] is an out-of-bounds\nwrite.\n\nValidate reallocationTableLen as the entry count it is, with\nstruct_size()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - A crafted UDF image must be presented and mounted as local loop or removable block media; no network-facing path reaches this parser.\nAC:L - The attacker deterministically controls the entry count, table contents, block size, and accessed packet, with no race or condition outside attacker control.\nPR:L - Direct mounting requires initial-namespace CAP_SYS_ADMIN and user namespaces do not help, but common UDisks/polkit configurations let an active unprivileged local user mount attacker-controlled loop or removable media through a privileged broker.\nUI:N - The local attacker can request the brokered mount and trigger block translation themselves, requiring no action by a separate victim.\nS:U - Exploitation compromises the host kernel within its existing security authority and does not inherently cross a VM, IOMMU, or other scope boundary.\nC:H - The malformed count permits reads up to roughly eight times beyond the block, and relocation can expose adjacent kernel data through copied entries or returned mapping values.\nI:H - udf_relocate_blocks performs an out-of-bounds origLocation store and attacker-sized memmove through mapEntry[], potentially corrupting adjacent kernel pages and enabling control-flow hijacking.\nA:H - The extensive out-of-bounds reads and writes can reliably cause a kernel oops, panic, or fatal memory corruption."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/udf/super.c"],"versions":[{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e","status":"affected","versionType":"git"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9","status":"affected","versionType":"git"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"2d726135099313958f8975532a2e15322ff150ce","status":"affected","versionType":"git"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"7285276aa50d2839afb5957ffd491ad282dc8f72","status":"affected","versionType":"git"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"2a219acb2ce674d99bbd1b7b35ed8c384dac7200","status":"affected","versionType":"git"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"04f4599a9efb90992d072a814960edf0cd62805d","status":"affected","versionType":"git"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"7f7774b9da0ef17b87bfa238cf966ad0b3376150","status":"affected","versionType":"git"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"3ec997bd5508e9b25210b5bbec89031629cdb093","status":"affected","versionType":"git"},{"version":"e240873cb4a9fd18de60a817100a96fe670d4359","status":"affected","versionType":"git"},{"version":"9ae30e324a96d0328a575329d7a95a09b3318601","status":"affected","versionType":"git"},{"version":"b1c5701ad6b3e5d21d16f65475651cfaaa41e7aa","status":"affected","versionType":"git"},{"version":"a9f1af04f086656246f30354fb4564ce3b08c4a0","status":"affected","versionType":"git"},{"version":"4836ee563d65bb492f907cbe267a5761b9693e4d","status":"affected","versionType":"git"},{"version":"2.6.32.60","lessThan":"2.6.33","status":"affected","versionType":"semver"},{"version":"2.6.34.14","lessThan":"2.6.35","status":"affected","versionType":"semver"},{"version":"3.0.37","lessThan":"3.1","status":"affected","versionType":"semver"},{"version":"3.2.23","lessThan":"3.3","status":"affected","versionType":"semver"},{"version":"3.4.5","lessThan":"3.5","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/udf/super.c"],"versions":[{"version":"3.5","status":"affected"},{"version":"0","lessThan":"3.5","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.12.96"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"7.1.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32.60"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34.14"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.37"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2.23"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4.5"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e"},{"url":"https://git.kernel.org/stable/c/0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9"},{"url":"https://git.kernel.org/stable/c/2d726135099313958f8975532a2e15322ff150ce"},{"url":"https://git.kernel.org/stable/c/7285276aa50d2839afb5957ffd491ad282dc8f72"},{"url":"https://git.kernel.org/stable/c/2a219acb2ce674d99bbd1b7b35ed8c384dac7200"},{"url":"https://git.kernel.org/stable/c/04f4599a9efb90992d072a814960edf0cd62805d"},{"url":"https://git.kernel.org/stable/c/7f7774b9da0ef17b87bfa238cf966ad0b3376150"},{"url":"https://git.kernel.org/stable/c/3ec997bd5508e9b25210b5bbec89031629cdb093"}],"title":"udf: validate sparing table length as an entry count, not a byte count","x_generator":{"engine":"bippy-1.2.0"}}}}