udf: validate VAT header length against the VAT inode size
Summary
| CVE | CVE-2026-64323 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-25 10:17:13 UTC |
| Updated | 2026-07-27 05:16:42 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it against the VAT inode size: map->s_type_specific.s_virtual.s_start_offset = le16_to_cpu(vat20->lengthHeader); map->s_type_specific.s_virtual.s_num_entries = (sbi->s_vat_inode->i_size - map->s_type_specific.s_virtual.s_start_offset) >> 2; lengthHeader is a fully attacker-controlled 16-bit value. If it exceeds the VAT inode size, the s_num_entries subtraction underflows to a huge count, which defeats the "block > s_num_entries" bound in udf_get_pblock_virt15(); and on the ICB-inline path that function reads ((__le32 *)(iinfo->i_data + s_start_offset))[block] so a large s_start_offset indexes past the inode's in-ICB data. Mounting a crafted UDF image with a virtual (VAT) partition then triggers an out-of-bounds read. Reject a VAT whose header length does not leave room for at least one entry within the VAT inode. |
Risk And Classification
Primary CVSS: v3.1 7.1 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS: 0.001600000 probability, percentile 0.055770000 (date 2026-07-29)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
| 3.1 | CNA | DECLARED | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected fa5e08156335d0687c85b4e724db9448fb166601 0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934 git | Not specified |
| CNA | Linux | Linux | affected fa5e08156335d0687c85b4e724db9448fb166601 883962731420ec271ed8c1cd76524f4b17faa982 git | Not specified |
| CNA | Linux | Linux | affected fa5e08156335d0687c85b4e724db9448fb166601 2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63 git | Not specified |
| CNA | Linux | Linux | affected fa5e08156335d0687c85b4e724db9448fb166601 bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb git | Not specified |
| CNA | Linux | Linux | affected fa5e08156335d0687c85b4e724db9448fb166601 55287a3555ff0515b3aff181d2c08c0462a41709 git | Not specified |
| CNA | Linux | Linux | affected fa5e08156335d0687c85b4e724db9448fb166601 e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad git | Not specified |
| CNA | Linux | Linux | affected fa5e08156335d0687c85b4e724db9448fb166601 74580fdf022909e184223cacc364feb826982d96 git | Not specified |
| CNA | Linux | Linux | affected fa5e08156335d0687c85b4e724db9448fb166601 d8202786b3d75125c84ebc4de6d946f92fde0ee8 git | Not specified |
| CNA | Linux | Linux | affected 2.6.26 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.26 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.261 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.212 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.178 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.145 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.96 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.39 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.4 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/883962731420ec271ed8c1cd76524f4b17faa982 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d8202786b3d75125c84ebc4de6d946f92fde0ee8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/74580fdf022909e184223cacc364feb826982d96 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/55287a3555ff0515b3aff181d2c08c0462a41709 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.