Heap-based buffer overflow in Linux kernel - CVE-2026-45991

 

Heap-based buffer overflow in Linux kernel - CVE-2026-45991

Published: May 28, 2026


Vulnerability identifier: #VU132500
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45991
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in part_descs_loc[] handling in handle_partition_descriptor() when mounting a crafted UDF image with repeated partition descriptors. A local user can supply a specially crafted UDF image to cause a denial of service.


Affected software

Linux kernel
Anolis OS
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
openEuler
Ubuntu
kernel (Red Hat package)
kernel-devel
perf
kernel-tools-libs-devel
python3-perf
kernel-tools-libs
kernel-tools
kernel-abi-stablelists
kernel-doc
kernel-modules-extra
kernel-modules
kernel-headers
kernel-debug-modules-extra
bpftool
kernel
kernel-core
kernel-cross-headers
kernel-debug
kernel-debug-core
kernel-debug-devel
kernel-debug-modules
kernel-tools-debuginfo
kernel-source
kernel-debugsource
kernel-tools-devel
kernel-debuginfo
perf-debuginfo
python3-perf-debuginfo
bpftool-debuginfo
linux (Ubuntu package)
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-aws (Ubuntu package)
linux-raspi (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)

How to mitigate CVE-2026-45991

Install security update from vendor's repository.

kernel (Red Hat package) - update to 4.18.0-553.155.1.el8_10
kernel-devel - update to 4.18.0-553.155.1.0.1
perf - update to 4.18.0-553.155.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.155.1.0.1
python3-perf - update to 4.18.0-553.155.1.0.1
kernel-tools-libs - update to 4.18.0-553.155.1.0.1
kernel-tools - update to 4.18.0-553.155.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.155.1.0.1
kernel-doc - update to 4.18.0-553.155.1.0.1
kernel-modules-extra - update to 4.18.0-553.155.1.0.1
kernel-modules - update to 4.18.0-553.155.1.0.1
kernel-headers - update to 4.18.0-553.155.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.155.1.0.1
bpftool - update to 4.18.0-553.155.1.0.1
kernel - update to 4.18.0-553.155.1.0.1
kernel-core - update to 4.18.0-553.155.1.0.1
kernel-cross-headers - update to 4.18.0-553.155.1.0.1
kernel-debug - update to 4.18.0-553.155.1.0.1
kernel-debug-core - update to 4.18.0-553.155.1.0.1
kernel-debug-devel - update to 4.18.0-553.155.1.0.1
kernel-debug-modules - update to 4.18.0-553.155.1.0.1
bpftool - update to 5.10.0-318.0.0.221
kernel - update to 5.10.0-318.0.0.221
python3-perf - update to 5.10.0-318.0.0.221
kernel-tools-debuginfo - update to 5.10.0-318.0.0.221
kernel-tools - update to 5.10.0-318.0.0.221
kernel-source - update to 5.10.0-318.0.0.221
kernel-headers - update to 5.10.0-318.0.0.221
kernel-devel - update to 5.10.0-318.0.0.221
kernel-debugsource - update to 5.10.0-318.0.0.221
kernel-tools-devel - update to 5.10.0-318.0.0.221
perf - update to 5.10.0-318.0.0.221
kernel-debuginfo - update to 5.10.0-318.0.0.221
perf-debuginfo - update to 5.10.0-318.0.0.221
python3-perf-debuginfo - update to 5.10.0-318.0.0.221
bpftool-debuginfo - update to 5.10.0-318.0.0.221
linux (Ubuntu package) - addressed in versions 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2, 7.0.0-27.27
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1, 7.0.0-1013.13
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-aws (Ubuntu package) - update to 6.8.0-1061.64+1
linux-raspi (Ubuntu package) - addressed in versions 6.8.0-1061.65, 6.8.0-2050.52, 7.0.0-1014.14
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1, 7.0.0-1009.9, 7.0.0-1010.10
linux-azure-fips (Ubuntu package) - update to 6.8.0-1063.71+fips2
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1

External References

Related Security Bulletins