SB20260918157 - Out-of-bounds read in Linux kernel udf
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-93055)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in udf_pc_to_char() when processing malformed UDF symlink data containing a partial pathComponent header. A local user can provide malformed UDF symlink data containing a partial pathComponent header to cause an out-of-bounds read.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/48b2a74317e15f93983c74a5a07245bc94a00d39
- https://git.kernel.org/stable/c/57371e743398e0d485f0f7beede1ade41f812324
- https://git.kernel.org/stable/c/8da8fd3df9fc14cf79ca3a3978d27ba067985111
- https://git.kernel.org/stable/c/b21cb958292ee1e02eb305ff9de09f2f7edd551a
- https://git.kernel.org/stable/c/d23eb7380d1594cda31a5dc8487dd2a5c8def8c7
- https://git.kernel.org/stable/c/d9f49c8b55debf1512f912077b6c759cc8b6d2e0
- https://git.kernel.org/stable/c/ee264227b656218bc1b257d8e4f83467f5f17723
- https://git.kernel.org/stable/c/f44f5f795f1a56249821a05183347ea025855e31