Use-after-free in Linux kernel - CVE-2026-63808
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in exfat_find_dir_entry() when parsing a crafted exFAT filesystem image. A local user can supply a crafted exFAT image to trigger a kernel fault and cause a denial of service.
The issue occurs on the TYPE_EXTEND path after a directory entry buffer is released and then dereferenced.
Affected software
How to mitigate CVE-2026-63808
External References
- https://git.kernel.org/stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359
- https://git.kernel.org/stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8
- https://git.kernel.org/stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649
- https://git.kernel.org/stable/c/708b97e792945d3e4653939fd3405d71a61ad065
- https://git.kernel.org/stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433
- https://git.kernel.org/stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86
- https://git.kernel.org/stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef
- https://git.kernel.org/stable/c/e6f1a11cfb808441a43ffae9b476cc135732cd27