Executive brief
A vulnerability in the Linux kernel's exFAT file system driver could allow a local user or a malicious storage device to cause a system crash. The issue occurs when the system attempts to read directory entries from a specially crafted exFAT-formatted drive. This could lead to a denial-of-service (system crash), impacting the availability of the affected machine.
Technical details
A use-after-free (UAF) vulnerability exists in the exfat_find_dir_entry() function within the Linux kernel's exFAT driver. The root cause is a premature call to brelse(bh), which releases the buffer head reference before the code finishes dereferencing a pointer (ep) that points into the buffer's data. An attacker can trigger this by providing a crafted exFAT image with specific directory entry structures (e.g., long filenames with hash collisions) that force the code into the TYPE_EXTEND path. While primarily a denial-of-service risk via kernel panic, UAF vulnerabilities can sometimes have broader security implications. The issue has been resolved by moving the brelse() call to occur only after all dereferences are complete.
Affected products
- Linux Linux Kernel ca06197382bd to e6f1a11cfb80
Timeline
- 2026-04-22: other: Patch authored
- 2026-06-15: patched: Patch committed to stable tree
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359
- https://git.kernel.org/stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8
- https://git.kernel.org/stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649
- https://git.kernel.org/stable/c/708b97e792945d3e4653939fd3405d71a61ad065
- https://git.kernel.org/stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433
- https://git.kernel.org/stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86
- https://git.kernel.org/stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef