Junglewise Threat Intelligence

CVE-2026-64074: Linux Kernel slab out-of-bounds write in statmount_mnt_idmap

CVE-2026-64074 · Severity: info · CVSS 6.2 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's file system mounting component. It could allow a local user to cause a system crash or instability by triggering a memory corruption error during specific mount information requests. This affects the reliability of the operating system but typically requires local access to exploit.

Technical details

A 1-byte NULL out-of-bounds write exists in fs/statmount due to improper overflow handling in statmount_mnt_idmap(). The function manually increments the sequence file count (seq->count) after a seq_printf() call. If seq_printf() overflows, it sets the count to the buffer size; the subsequent manual increment pushes the count to size + 1, causing seq_has_overflowed() to fail its check. This corrupted count is later used as an index for a NUL byte assignment in statmount_string(), resulting in a slab-out-of-bounds write. The issue is fixed by adding an immediate overflow check after the seq_printf() call.

Affected products

  • Linux Linux Kernel 6.15 to 6.18.34, 7.0.11

Timeline

  • 2026-05-04: disclosed: Initial patch submitted by Junyoung Jang
  • 2026-07-19: advisory: CVE-2026-64074 published

References

Related threats