« Volver al listado

CVE-2026-64324

Estado: AnalizadaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

udf: validate free block extents against the partition length

udf_free_blocks() checks the logical block number and count against the partition length, but drops the extent offset from that final bound. A crafted extent can pass the guard while logicalBlockNum + offset + count points past the partition, which later indexes past the space bitmap array.

A single ftruncate(2) on a file backed by such an extent reliably panics the kernel. This is a local availability issue.

Leer descripción completaMostrar menos

On desktop systems where UDisks/polkit allows the active user to mount removable UDF media without CAP_SYS_ADMIN, an unprivileged local user can supply the crafted filesystem and trigger the panic by truncating a writable file on it. Systems that require root or CAP_SYS_ADMIN to mount the image have a higher prerequisite.

No confidentiality or integrity impact is claimed: the reproduced primitive is an out-of-bounds read of a bitmap pointer slot followed by a kernel panic.

Use the already computed logicalBlockNum + offset + count value for the partition length check. Also make load_block_bitmap() reject an out-of-range block group before indexing s_block_bitmap[], so corrupted callers cannot walk past the flexible array.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local sin interacción del usuario (AV:L/PR:L/UI:N) que causa panic del kernel mediante ftruncate() → T1068. Impacto: DoS por lectura fuera de límites (T1499.004) y acceso a datos de bitmap (T1005).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64324",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "934f815345c09c290a9b9a9cfdddc203ec2117e8",
              "lessThan": "fdd6229d2ae9914c1f25d1041db0f4f312a4fa76",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "22cc7323f090646c8cfb5939e6f15bdc2ed3fd27",
              "lessThan": "b54aee5652fcd7c23a0904a4623ec462c3edc70c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7c4fa9ebfce69619d132fe703dc2e2cf62a13723",
              "lessThan": "12af328d2ee8d68e81ba612246d0b54b22d23e1f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5cc9745e2ea11aef7d5c9a42bc36f6cd3e1b4cc3",
              "lessThan": "fb49099206c5c57af28a157249fa7bcb5518f99e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "56e69e59751d20993f243fb7dd6991c4e522424c",
              "lessThan": "9442d75429b0c556292a7454fe888d54259f5240",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "56e69e59751d20993f243fb7dd6991c4e522424c",
              "lessThan": "335202ab25b01fdd45889ff25eab70864686dea3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "56e69e59751d20993f243fb7dd6991c4e522424c",
              "lessThan": "be87de7789a82a030a4896bc7683415ec9fa6f2b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "56e69e59751d20993f243fb7dd6991c4e522424c",
              "lessThan": "5f0419457f89dce1a3f1c8e62a3adf2f39ab8168",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "097420e48e30f51e8f4f650b5c946f5af63ec1a3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5def895b42ef16a2da6402818cba8d7ec8ede1ef",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05fb2bf477d3fe5421bd4cb699574737f52bd88b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.224",
              "lessThan": "5.10.261",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.165",
              "lessThan": "5.15.212",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.105",
              "lessThan": "6.1.178",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.46",
              "lessThan": "6.6.145",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.19.320",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.282",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.10.5",
              "lessThan": "6.11",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/udf/balloc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.96",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/udf/balloc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-25T10:17:13.923",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/12af328d2ee8d68e81ba612246d0b54b22d23e1f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/335202ab25b01fdd45889ff25eab70864686dea3",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5f0419457f89dce1a3f1c8e62a3adf2f39ab8168",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9442d75429b0c556292a7454fe888d54259f5240",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b54aee5652fcd7c23a0904a4623ec462c3edc70c",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/be87de7789a82a030a4896bc7683415ec9fa6f2b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fb49099206c5c57af28a157249fa7bcb5518f99e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fdd6229d2ae9914c1f25d1041db0f4f312a4fa76",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-129"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate free block extents against the partition length\n\nudf_free_blocks() checks the logical block number and count against the\npartition length, but drops the extent offset from that final bound.  A\ncrafted extent can pass the guard while logicalBlockNum + offset + count\npoints past the partition, which later indexes past the space bitmap\narray.\n\nA single ftruncate(2) on a file backed by such an extent reliably\npanics the kernel.  This is a local availability issue.  On desktop\nsystems where UDisks/polkit allows the active user to mount removable\nUDF media without CAP_SYS_ADMIN, an unprivileged local user can supply\nthe crafted filesystem and trigger the panic by truncating a writable\nfile on it.  Systems that require root or CAP_SYS_ADMIN to mount the\nimage have a higher prerequisite.\n\nNo confidentiality or integrity impact is claimed: the reproduced\nprimitive is an out-of-bounds read of a bitmap pointer slot followed by\na kernel panic.\n\nUse the already computed logicalBlockNum + offset + count value for the\npartition length check.  Also make load_block_bitmap() reject an\nout-of-range block group before indexing s_block_bitmap[], so corrupted\ncallers cannot walk past the flexible array."
    }
  ],
  "lastModified": "2026-09-04T14:51:53.050",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9C1FD3D-3B79-4FC6-83B1-93C7ADA040CD",
              "versionEndExcluding": "4.20",
              "versionStartIncluding": "4.19.320"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE43A6BA-7656-432B-BD46-2A1EB5073A85",
              "versionEndExcluding": "5.5",
              "versionStartIncluding": "5.4.282"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C138EEFB-45D2-444D-8497-B77509009C44",
              "versionEndExcluding": "5.10.261",
              "versionStartIncluding": "5.10.224"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71E1BEFF-4FE7-43A3-ACF4-FD45EC255909",
              "versionEndExcluding": "5.15.212",
              "versionStartIncluding": "5.15.165"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C944DC1C-B6D8-4A18-9B1C-EDC7F8AF150C",
              "versionEndExcluding": "6.1.178",
              "versionStartIncluding": "6.1.105"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E73FA84-8695-4B43-8134-B743C74588A3",
              "versionEndExcluding": "6.6.145",
              "versionStartIncluding": "6.6.46"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82992A2E-D959-4C76-A628-D145730B9EC4",
              "versionEndExcluding": "6.12.96",
              "versionStartIncluding": "6.10.5"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "914AE4BC-3D59-4C5A-9DB5-9CE327B429F7",
              "versionEndExcluding": "6.18.39",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6228DDD6-4557-4AA3-9F43-AB995D471E42",
              "versionEndExcluding": "7.1.4",
              "versionStartIncluding": "6.19"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}