CVE-2026-89525: fallo en Linux
udf: reject VAT indexes equal to the entry count
Publicada el · Actualizada el
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 0.2%
probabilidad de explotación
0.2%top 93% de las CVE
explotación observada
noninguna fuente lo reporta
In the Linux kernel, the following vulnerability has been resolved:
udf: reject VAT indexes equal to the entry count
UDF 1.50 virtual partition mapping uses the VAT as an array of physical
block mappings. s_num_entries stores the number of entries in that array,
not the highest valid index. The valid VAT indexes are therefore below
s_num_entries.
udf_get_pblock_virt15() currently rejects only indexes greater than
s_num_entries. A crafted image can request index s_num_entries, pass the
bounds check, and make the kernel read one entry past the allocated VAT table.
Change the check to reject block >= s_num_entries, so the count is handled as
an exclusive upper bound.
A crafted UDF image reproduced this on origin/master commit
0e35b9b6ec0ffcc5e23cbdec09f5c622ad532b53 with a KASAN slab-out-of-bounds
report in udf_get_pblock_virt15().
Trail of Bits has a reproducer that triggers kernel panic demonstrating the bug, and can share it if needed.
Productos afectados
Linux · LinuxCVEs relacionadas — Linux
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referencias
https://git.kernel.org/stable/c/19f36c6453cd88fe6d60ef36ab1f1cad8ddf4ce4https://git.kernel.org/stable/c/1bd7947f1463c21edafa256d0fbec5b99215e2b6https://git.kernel.org/stable/c/8a8c1c42a34349a0626d910abbad5a29136446b7https://git.kernel.org/stable/c/9193368408d792cec2057628d87862140fb1ce1chttps://git.kernel.org/stable/c/b77b83f5529a26d084d64ece98abd6f0cc86e053https://git.kernel.org/stable/c/b95c33a4e743874f1b0a45bf2aaa4da553552bd1https://git.kernel.org/stable/c/cac0cb07f29ccfb373fd4a36c81e908ef3ce608chttps://git.kernel.org/stable/c/f64e01a90326bb85a3cc8aa0199931dc2f15b589