๐Ÿ” CVE Alert

CVE-2026-89525

UNKNOWN 0.0

udf: reject VAT indexes equal to the entry count

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: udf: reject VAT indexes equal to the entry count UDF 1.50 virtual partition mapping uses the VAT as an array of physical block mappings. s_num_entries stores the number of entries in that array, not the highest valid index. The valid VAT indexes are therefore below s_num_entries. udf_get_pblock_virt15() currently rejects only indexes greater than s_num_entries. A crafted image can request index s_num_entries, pass the bounds check, and make the kernel read one entry past the allocated VAT table. Change the check to reject block >= s_num_entries, so the count is handled as an exclusive upper bound. A crafted UDF image reproduced this on origin/master commit 0e35b9b6ec0ffcc5e23cbdec09f5c622ad532b53 with a KASAN slab-out-of-bounds report in udf_get_pblock_virt15(). Trail of Bits has a reproducer that triggers kernel panic demonstrating the bug, and can share it if needed.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f64e01a90326bb85a3cc8aa0199931dc2f15b589 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8a8c1c42a34349a0626d910abbad5a29136446b7 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 19f36c6453cd88fe6d60ef36ab1f1cad8ddf4ce4 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b77b83f5529a26d084d64ece98abd6f0cc86e053 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9193368408d792cec2057628d87862140fb1ce1c 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b95c33a4e743874f1b0a45bf2aaa4da553552bd1 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1bd7947f1463c21edafa256d0fbec5b99215e2b6 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cac0cb07f29ccfb373fd4a36c81e908ef3ce608c
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f64e01a90326bb85a3cc8aa0199931dc2f15b589 git.kernel.org: https://git.kernel.org/stable/c/8a8c1c42a34349a0626d910abbad5a29136446b7 git.kernel.org: https://git.kernel.org/stable/c/19f36c6453cd88fe6d60ef36ab1f1cad8ddf4ce4 git.kernel.org: https://git.kernel.org/stable/c/b77b83f5529a26d084d64ece98abd6f0cc86e053 git.kernel.org: https://git.kernel.org/stable/c/9193368408d792cec2057628d87862140fb1ce1c git.kernel.org: https://git.kernel.org/stable/c/b95c33a4e743874f1b0a45bf2aaa4da553552bd1 git.kernel.org: https://git.kernel.org/stable/c/1bd7947f1463c21edafa256d0fbec5b99215e2b6 git.kernel.org: https://git.kernel.org/stable/c/cac0cb07f29ccfb373fd4a36c81e908ef3ce608c