Junglewise Threat Intelligence

CVE-2026-64322: Linux Kernel OOB read and write in UDF sparing table validation

CVE-2026-64322 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's handling of UDF file systems, which are commonly used on optical media like DVDs. By using a specially crafted disk image, an attacker could cause the system to read or write data outside of intended memory boundaries. This could lead to system instability, crashes, or potentially unauthorized access to sensitive information stored in memory.

Technical details

An out-of-bounds (OOB) read and write vulnerability exists in the Linux kernel UDF implementation within `udf_load_sparable_map()`. The root cause is a logic error where `reallocationTableLen` is validated as a byte count rather than an entry count. Because the table is subsequently processed as an array of 8-byte `sparingEntry` elements, a crafted UDF image can bypass the block size check, leading to OOB reads in `udf_get_pblock_spar15()` and OOB writes in `udf_relocate_blocks()` via `memmove()`. An attacker with the ability to mount a malicious UDF image could exploit this to crash the system or potentially achieve kernel-level code execution. The issue has been patched by using `struct_size()` to correctly validate the entry count against the block size.

Affected products

  • Linux Linux Kernel 1df2ae31c724 to eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e

Timeline

  • 2026-06-12: other: Vulnerability reported by researcher
  • 2026-07-18: patched: Fix committed to stable branches
  • 2026-07-25: disclosed: CVE published

References

Related threats