Executive brief
A vulnerability was identified in the Linux kernel's file system mounting component. It could allow a local user to cause a system crash or instability by triggering a memory corruption error during specific mount information requests. This affects the reliability of the operating system but typically requires local access to exploit.
Technical details
A 1-byte NULL out-of-bounds write exists in fs/statmount due to improper overflow handling in statmount_mnt_idmap(). The function manually increments the sequence file count (seq->count) after a seq_printf() call. If seq_printf() overflows, it sets the count to the buffer size; the subsequent manual increment pushes the count to size + 1, causing seq_has_overflowed() to fail its check. This corrupted count is later used as an index for a NUL byte assignment in statmount_string(), resulting in a slab-out-of-bounds write. The issue is fixed by adding an immediate overflow check after the seq_printf() call.
Affected products
- Linux Linux Kernel 6.15 to 6.18.34, 7.0.11
Timeline
- 2026-05-04: disclosed: Initial patch submitted by Junyoung Jang
- 2026-07-19: advisory: CVE-2026-64074 published