Out-of-bounds read in Linux kernel - CVE-2026-63814
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in f2fs_acl_from_disk() when parsing a malformed ACL xattr. A local user can supply a crafted ACL entry layout to trigger an out-of-bounds read and cause a denial of service.
The issue occurs because ACL_USER or ACL_GROUP entries can be placed in a slot that contains only a short ACL entry.
Affected software
How to mitigate CVE-2026-63814
External References
- https://git.kernel.org/stable/c/1ddf3fd21c4c652f9cab5552515c04a166662306
- https://git.kernel.org/stable/c/442ca20c54038e2400cf28aaa944cf1de2c8e65d
- https://git.kernel.org/stable/c/4e2a96ec7236e248e706850568e0a925fd21b588
- https://git.kernel.org/stable/c/5d8a39649947a4e86c8fbc682d7fc0041b8d109a
- https://git.kernel.org/stable/c/733cd8474e6d763d75ed96f3f2b98a25480cf2b9
- https://git.kernel.org/stable/c/aba4f94ac1832c7299c33e1b4fe5f87eef6dc8f1
- https://git.kernel.org/stable/c/c4810ada31e80cbe4011467c4f3b1e93f94134f3
- https://git.kernel.org/stable/c/ff83de56882cb8466184d322abece2589258ca56