« Volver al listado

CVE-2026-64544

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents

pefile_digest_pe_contents() computes the trailing-data hash length as pelen - (hashed_bytes + certs_size). A crafted PE can make the addition exceed pelen, causing the unsigned subtraction to underflow to ~4 GiB. This is passed to crypto_shash_update() which reads out of bounds and panics on unmapped vmalloc guard pages.

Validate that the addition does not overflow and the result does not exceed pelen before the subtraction. Return -ELIBBAD on failure.

Detalles técnicos trazas, registros y código del informe original
 BUG: unable to handle page fault for address: ffffc900038d8000
 Oops: Oops: 0000 [#1] SMP KASAN NOPTI
 RIP: 0010:sha256_blocks_generic (lib/crypto/sha256.c:152)
 Call Trace:
  <TASK>
  __sha256_update (lib/crypto/sha256.c:208)
  crypto_sha256_update (crypto/sha256.c:142)
  verify_pefile_signature (crypto/asymmetric_keys/verify_pefile.c:436)
  kexec_kernel_verify_pe_sig (kernel/kexec_file.c:151)
  __do_sys_kexec_file_load (kernel/kexec_file.c:406)
  do_syscall_64 (arch/x86/entry/syscall_64.c:94)
  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
  </TASK>
 Kernel panic - not syncing: Fatal exception

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64544",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
              "lessThan": "89efd998470a93284b7ad5a20d4e0e3c6858ae8e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
              "lessThan": "7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
              "lessThan": "b798ada5a5d1cb4cc4cfa72074b1b463eca6c506",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
              "lessThan": "627938383761fb4334b41ebe7ef438d6b8b19d60",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
              "lessThan": "e162bc386e71b5412425a38ee048e8d2185491b9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
              "lessThan": "6acd2fbd00f9c72aebefce63fc2e73e8f3d79061",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
              "lessThan": "803591785d33cf13b6f73ce2796e8b9e6d5e6526",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "af316fc442ef23901bbfcec5af55e69ca6ce9563",
              "lessThan": "f7dd32c5179d7755de18e21d5674b08f9e5cb180",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "crypto/asymmetric_keys/verify_pefile.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "crypto/asymmetric_keys/verify_pefile.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-27T21:17:06.980",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/627938383761fb4334b41ebe7ef438d6b8b19d60",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6acd2fbd00f9c72aebefce63fc2e73e8f3d79061",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/803591785d33cf13b6f73ce2796e8b9e6d5e6526",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/89efd998470a93284b7ad5a20d4e0e3c6858ae8e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b798ada5a5d1cb4cc4cfa72074b1b463eca6c506",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e162bc386e71b5412425a38ee048e8d2185491b9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f7dd32c5179d7755de18e21d5674b08f9e5cb180",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents\n\npefile_digest_pe_contents() computes the trailing-data hash length as\npelen - (hashed_bytes + certs_size). A crafted PE can make the addition\nexceed pelen, causing the unsigned subtraction to underflow to ~4 GiB.\nThis is passed to crypto_shash_update() which reads out of bounds and\npanics on unmapped vmalloc guard pages.\n\n BUG: unable to handle page fault for address: ffffc900038d8000\n Oops: Oops: 0000 [#1] SMP KASAN NOPTI\n RIP: 0010:sha256_blocks_generic (lib/crypto/sha256.c:152)\n Call Trace:\n  <TASK>\n  __sha256_update (lib/crypto/sha256.c:208)\n  crypto_sha256_update (crypto/sha256.c:142)\n  verify_pefile_signature (crypto/asymmetric_keys/verify_pefile.c:436)\n  kexec_kernel_verify_pe_sig (kernel/kexec_file.c:151)\n  __do_sys_kexec_file_load (kernel/kexec_file.c:406)\n  do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n  </TASK>\n Kernel panic - not syncing: Fatal exception\n\nValidate that the addition does not overflow and the result does not\nexceed pelen before the subtraction. Return -ELIBBAD on failure."
    }
  ],
  "lastModified": "2026-08-17T05:17:59.547",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}