Review reviewHigh

CVE-2026-64323

Linux

In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it against the VAT inode size: map->s_type_specific.s_virtual.s_start_offset = le16_to_cpu(vat20->lengthHeader); map->s_type_specific.s_virtual.s_num_entries = (sbi->s_vat_inode->i_size - map->s_type_specific.s_virtual.s_start_offset) >> 2; lengthHeader is a fully attacker-controlled 16-bit value. If it exceeds the VAT inode size, the s_num_entries sub...

CVSS
7.1
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it against the VAT inode size: map->s_type_specific.s_virtual.s_start_offset = le16_to_cpu(vat20->lengthHeader); map->s_type_specific.s_virtual.s_num_entries = (sbi->s_vat_inode->i_size - map->s_type_specific.s_virtual.s_start_offset) >> 2; lengthHeader is a fully attacker-controlled 16-bit value. If it exceeds the VAT inode size, the s_num_entries sub...

Affected product and versions

Product
Linux
Affected versions
>= fa5e08156335d0687c85b4e724db9448fb166601 < 0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934, >= fa5e08156335d0687c85b4e724db9448fb166601 < 883962731420ec271ed8c1cd76524f4b17faa982, >= fa5e08156335d0687c85b4e724db9448fb166601 < 2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63, >= fa5e08156335d0687c85b4e724db9448fb166601 < bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb, >= fa5e08156335d0687c85b4e724db9448fb166601 < 55287a3555ff0515b3aff181d2c08c0462a41709, >= fa5e08156335d0687c85b4e724db9448fb166601 < e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad, >= fa5e08156335d0687c85b4e724db9448fb166601 < 74580fdf022909e184223cacc364feb826982d96, >= fa5e08156335d0687c85b4e724db9448fb166601 < d8202786b3d75125c84ebc4de6d946f92fde0ee8, >= 2.6.26
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
Not available