CVE-2026-64323
Last modified
CVE-2026-64323 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it against the VAT inode size: map->s_type_specific.s_virtual.s_start_offset = le16_to_cpu(vat20->lengthHeader); map->s_type_specific.s_virtual.s_num_entries = (sbi->s_vat_inode->i_size - map->s_type_specific.s_virtual.s_start_offset) >> 2; lengthHeader is a fully attacker-controlled 16-bit value. If it exceeds the VAT inode size, the s_num_entries subtraction underflows to a huge count, which defeats the "block > s_num_entries" bound in udf_get_pblock_virt15(); and on the ICB-inline path that function reads ((__le32 *)(iinfo->i_data + s_start_offset))[block] so a large s_start_offset indexes past the inode's in-ICB data. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it against the VAT inode size: map->s_type_specific.s_virtual.s_start_offset = le16_to_cpu(vat20->lengthHeader); map->s_type_specific.s_virtual.s_num_entries = (sbi->s_vat_inode->i_size - map->s_type_specific.s_virtual.s_start_offset) >> 2; lengthHeader is a fully attacker-controlled 16-bit value. If it exceeds the VAT inode size, the s_num_entries subtraction underflows to a huge count, which defeats the "block > s_num_entries" bound in udf_get_pblock_virt15(); and on the ICB-inline path that function reads ((__le32 *)(iinfo->i_data + s_start_offset))[block] so a large s_start_offset indexes past the inode's in-ICB data. Mounting a crafted UDF image with a virtual (VAT) partition then triggers an out-of-bounds read. Reject a VAT whose header length does not leave room for at least one entry within the VAT inode.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= fa5e08156335d0687c85b4e724db9448fb166601, < 0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934; >= fa5e08156335d0687c85b4e724db9448fb166601, < 883962731420ec271ed8c1cd76524f4b17faa982; >= fa5e08156335d0687c85b4e724db9448fb166601, < 2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63; >= fa5e08156335d0687c85b4e724db9448fb166601, < bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb; >= fa5e08156335d0687c85b4e724db9448fb166601, < 55287a3555ff0515b3aff181d2c08c0462a41709; >= fa5e08156335d0687c85b4e724db9448fb166601, < e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad; >= fa5e08156335d0687c85b4e724db9448fb166601, < 74580fdf022909e184223cacc364feb826982d96; >= fa5e08156335d0687c85b4e724db9448fb166601, < d8202786b3d75125c84ebc4de6d946f92fde0ee8 |
| Linux | Linux | 2.6.26 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64323?
How severe is CVE-2026-64323?
How do I fix CVE-2026-64323?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64318In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-64319In the Linux kernel, the following vulnerability has been re…9.1
- CVE-2026-6432Improper bounds validation in EmberZNet SDK versions 9.0.2 a…5.3
- CVE-2026-64320In the Linux kernel, the following vulnerability has been re…9.1
- CVE-2026-64321In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64322In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64324In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64325In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64326In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64327In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64328In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64329In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-64323?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
