CVE-2026-93828
Last modified
CVE-2026-93828 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: exfat: fix handling of damaged volume in exfat_create_upcase_table() When the size of the upcase table is set to zero in the dentry for any reason(e.g. corrupted media or misbehaving device), an integer overflow causes the module to loop indefinitely. If the size of the upcase table is read zero, do not attempt to load the table.
Description
In the Linux kernel, the following vulnerability has been resolved: exfat: fix handling of damaged volume in exfat_create_upcase_table() When the size of the upcase table is set to zero in the dentry for any reason(e.g. corrupted media or misbehaving device), an integer overflow causes the module to loop indefinitely. If the size of the upcase table is read zero, do not attempt to load the table. Instead, fallback to loading the default upcase table. If the size of the upcase table is zero or no upcase table is found, raise exfat_fs_error() to mark the volume read-only.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 370e812b3ec190fa492c9fd5a80c38b086d105c0, < 60ace93811609e4dd883e9de5fb4462ed834160a; >= 370e812b3ec190fa492c9fd5a80c38b086d105c0, < 2cc0b612343638057ef321ce735201a7c2f52f25; >= 370e812b3ec190fa492c9fd5a80c38b086d105c0, < 20dd3185d13865214ff25b0bf7b931e8d73be1ac |
| Linux | Linux | 5.7 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-93828?
How severe is CVE-2026-93828?
How do I fix CVE-2026-93828?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-93822In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93823In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93824In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93825In the Linux kernel, the following vulnerability has been re…
- CVE-2026-93826In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-93827In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-93829In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9383A vulnerability has been found in itsourcecode Electronic Ju…7.3
- CVE-2026-93830In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-93834A use-after-free vulnerability was found in QEMU's 9pfs subs…8.8
- CVE-2026-93836The WPC Product Bundles for WooCommerce plugin for WordPress…7.2
- CVE-2026-93838SGLang versions through 0.5.20 contain an unbounded memory a…5.9
Are you affected by CVE-2026-93828?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
