Executive brief
A vulnerability was identified in the Linux kernel's exFAT file system driver. The system fails to properly check the length of file names when reading directory entries from a disk. An attacker could use a specially crafted storage device or disk image to cause the system to write data outside of its intended memory area, potentially leading to a system crash or unauthorized modification of kernel memory.
Technical details
An out-of-bounds (OOB) read and write vulnerability exists in the Linux kernel's exFAT implementation within fs/exfat/dir.c. In the exfat_find_dir_entry() function, the pointer 'uniname' is advanced by a fixed amount (EXFAT_FILE_NAME_LEN) for each name entry, while the loop guard only validates the accumulated 'name_len'. By crafting a directory with multiple short name fragments containing early NUL terminators, an attacker can cause 'uniname' to advance beyond the allocated p_uniname->name buffer while 'name_len' remains below MAX_NAME_LENGTH. This results in OOB memory access when the kernel attempts to null-terminate the string. The issue has been resolved by tracking the per-entry write offset and rejecting fragments that would exceed the buffer limits.
Affected products
- Linux Linux Kernel ca06197382bd to 72a2589d82eb
Timeline
- 2026-06-12: other: Vulnerability reported by Bryam Vargas
- 2026-07-18: patched: Fix committed to stable kernel trees
- 2026-07-25: advisory: CVE-2026-64296 published
References
- https://git.kernel.org/stable/c/33c0b96d7e1672be1de0053786637ea46fb81507
- https://git.kernel.org/stable/c/3a1230e7b043c62737b05a3e9275ca83a43ad20a
- https://git.kernel.org/stable/c/727bf7783a2936ffd55c628dddfd69343e511dcf
- https://git.kernel.org/stable/c/72a2589d82eb001c94b74bcfe6f9a599bd9bef60
- https://git.kernel.org/stable/c/c8e041c68c0bbb73aa62371ee63947bb6949d8b2
- https://git.kernel.org/stable/c/ce4736c1e6c4cfbf1ac409a8c328a0b69546c9a0
- https://git.kernel.org/stable/c/cf85180b8a015029ee147694eaf4e0b3537e9432