Junglewise Threat Intelligence

CVE-2026-93055: Linux kernel UDF symlink out-of-bounds read in pathComponent parsing

CVE-2026-93055 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's UDF filesystem driver contains a vulnerability in its symlink handling that can lead to reading data beyond allocated memory. When processing a malformed UDF filesystem, the kernel can attempt to parse an incomplete pathComponent header without first validating that sufficient data remains, potentially exposing kernel memory or causing a system crash.

Technical details

The vulnerability is an out-of-bounds read in the UDF symlink parsing code (fs/udf/symlink.c). The udf_symlink_filler() function can call udf_pc_to_char() with a partial pathComponent header, causing the function to read beyond the allocated buffer when accessing the pathComponent structure. The root cause is a missing bounds check before dereferencing the pathComponent pointer. An attacker can trigger this by mounting a specially crafted UDF filesystem image locally, causing an information leak or denial of service. The fix adds a validation check to ensure enough input remains for a complete pathComponent header before accessing it, rejecting malformed symlink data with an -EIO error.

Affected products

  • Linux Linux kernel 2.6.12 and later (patched in 6.x and 7.x stable series)

Timeline

  • 2026-09-17: disclosed: Published to NVD
  • 2026-09-14: patched: Fix merged to Linux stable kernel branches

References

Related threats