Review reviewHigh

CVE-2026-53369

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. Reject such descriptors instead of silently accepting them. A legitimate single-block descriptor should never have a CRC length that exceeds the block.

CVSS
8.4
EPSS
0.14%
3.72% percentile
CISA KEV
Not listed
Published
2026.07.19
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.14%
Technical severityCVSS 8.4

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. Reject such descriptors instead of silently accepting them. A legitimate single-block descriptor should never have a CRC length that exceeds the block.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 832ab4a882dc9b3c0155490d9993642ef545fd22, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7d1b6adbf90df6c8941090d5646fbeca25ba9770, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3dede76d525919bb966f9213e131af685de5ff99, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 50dfaf4a027742b4fcdc3e9305e7199ece9bc6a6, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 31605bbe94557bff721eaf041001169d44ac6f98, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1873eb81c65d3f849418d7386baa39c439c9fc38, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fdb26e628d2a211a23815d375bd33bdf863344e2, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 55d41b0a20128e86b9e960dd2e3f0a2d69a18df7, >= 2.6.12, >= 2.6.12.1 < 5.10.258, >= 5.11 < 5.15.209, >= 5.16 < 6.1.175, >= 6.2 < 6.6.140, >= 6.7 < 6.12.88, >= 6.13 < 6.18.30, >= 6.19 < 7.0.7, 2.6.12, 7.1
Fixed versions
5.10.258, 5.15.209, 6.1.175, 6.6.140, 6.12.88, 6.18.30, 7.0.7

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available