Junglewise Threat Intelligence

CVE-2026-64296: Linux Kernel exFAT out-of-bounds write in exfat_find_dir_entry

CVE-2026-64296 · Severity: info · CVSS 6.2 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's exFAT file system driver. The system fails to properly check the length of file names when reading directory entries from a disk. An attacker could use a specially crafted storage device or disk image to cause the system to write data outside of its intended memory area, potentially leading to a system crash or unauthorized modification of kernel memory.

Technical details

An out-of-bounds (OOB) read and write vulnerability exists in the Linux kernel's exFAT implementation within fs/exfat/dir.c. In the exfat_find_dir_entry() function, the pointer 'uniname' is advanced by a fixed amount (EXFAT_FILE_NAME_LEN) for each name entry, while the loop guard only validates the accumulated 'name_len'. By crafting a directory with multiple short name fragments containing early NUL terminators, an attacker can cause 'uniname' to advance beyond the allocated p_uniname->name buffer while 'name_len' remains below MAX_NAME_LENGTH. This results in OOB memory access when the kernel attempts to null-terminate the string. The issue has been resolved by tracking the per-entry write offset and rejecting fragments that would exceed the buffer limits.

Affected products

  • Linux Linux Kernel ca06197382bd to 72a2589d82eb

Timeline

  • 2026-06-12: other: Vulnerability reported by Bryam Vargas
  • 2026-07-18: patched: Fix committed to stable kernel trees
  • 2026-07-25: advisory: CVE-2026-64296 published

References

Related threats