SB20260727259 - Out-of-bounds read in Linux kernel udf
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-64323)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in udf_load_vat() and udf_get_pblock_virt15() when mounting a crafted UDF image with a virtual (VAT) partition. A local user can provide a crafted UDF image with an oversized VAT header length to disclose sensitive information.
User interaction is required to mount the crafted filesystem image.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934
- https://git.kernel.org/stable/c/2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63
- https://git.kernel.org/stable/c/55287a3555ff0515b3aff181d2c08c0462a41709
- https://git.kernel.org/stable/c/74580fdf022909e184223cacc364feb826982d96
- https://git.kernel.org/stable/c/883962731420ec271ed8c1cd76524f4b17faa982
- https://git.kernel.org/stable/c/bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb
- https://git.kernel.org/stable/c/d8202786b3d75125c84ebc4de6d946f92fde0ee8
- https://git.kernel.org/stable/c/e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad