Out-of-bounds read in Linux kernel - CVE-2026-93055
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in udf_pc_to_char() when processing malformed UDF symlink data containing a partial pathComponent header. A local user can provide malformed UDF symlink data containing a partial pathComponent header to cause an out-of-bounds read.
Affected software
How to mitigate CVE-2026-93055
External References
- https://git.kernel.org/stable/c/48b2a74317e15f93983c74a5a07245bc94a00d39
- https://git.kernel.org/stable/c/57371e743398e0d485f0f7beede1ade41f812324
- https://git.kernel.org/stable/c/8da8fd3df9fc14cf79ca3a3978d27ba067985111
- https://git.kernel.org/stable/c/b21cb958292ee1e02eb305ff9de09f2f7edd551a
- https://git.kernel.org/stable/c/d23eb7380d1594cda31a5dc8487dd2a5c8def8c7
- https://git.kernel.org/stable/c/d9f49c8b55debf1512f912077b6c759cc8b6d2e0
- https://git.kernel.org/stable/c/ee264227b656218bc1b257d8e4f83467f5f17723
- https://git.kernel.org/stable/c/f44f5f795f1a56249821a05183347ea025855e31