SB2026072833 - Out-of-bounds read in Linux kernel asymmetric_keys
Published: July 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-64544)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in pefile_digest_pe_contents when processing a crafted PE file. A local user can supply a specially crafted PE file to cause a denial of service.
The issue occurs because an unsigned subtraction can underflow after the trailing-data hash length calculation exceeds the PE length, which can lead to a kernel panic on unmapped vmalloc guard pages.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/627938383761fb4334b41ebe7ef438d6b8b19d60
- https://git.kernel.org/stable/c/6acd2fbd00f9c72aebefce63fc2e73e8f3d79061
- https://git.kernel.org/stable/c/7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c
- https://git.kernel.org/stable/c/803591785d33cf13b6f73ce2796e8b9e6d5e6526
- https://git.kernel.org/stable/c/89efd998470a93284b7ad5a20d4e0e3c6858ae8e
- https://git.kernel.org/stable/c/b798ada5a5d1cb4cc4cfa72074b1b463eca6c506
- https://git.kernel.org/stable/c/e162bc386e71b5412425a38ee048e8d2185491b9
- https://git.kernel.org/stable/c/f7dd32c5179d7755de18e21d5674b08f9e5cb180