Out-of-bounds write in Linux kernel - CVE-2026-64432

 

Out-of-bounds write in Linux kernel - CVE-2026-64432

Published: July 27, 2026


Vulnerability identifier: #VU139511
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64432
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in log_replay in fs/ntfs3/fslog.c when mounting a crafted NTFS image and replaying the $LogFile journal. A local user can provide a specially crafted NTFS image to cause a denial of service or execute arbitrary code.

The issue can be triggered at mount time during the analysis pass when LCNs from an action log record are copied into an existing Dirty Page Table entry, and integer underflow in the target VCN delta can drive the destination index past the allocated page_lcns array.


Affected software

Linux kernel

How to mitigate CVE-2026-64432

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins