Answer in brief
CVE-2026-64318 records a Unknown severity vulnerability in partitions: aix: bound the pp_count scan to the ppe array. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64318 records a Unknown severity vulnerability in partitions: aix: bound the pp_count scan to the ppe array. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <09861651617ba0fec089e8b9477439e68398c110 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <5eacdb1967378f5e5591cd27a2d8cdee2df1a599 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <b5e9c09309e18fd9839ad007c238120353ca0cc4 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <fd94a779020f2ecc8b2607f4c20b34acb1763b9a || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <4671bb74bba05fdd4acf670a35758c29e8c97b83 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <ce93228e2193a17d2c58b656e439bb39fe5c3af8 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <44f37ee92fdcd377c41bdf6a31cdd8cc7d4c410e || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <2dc0bfd2fe355fb930de63c2f2eb8ced8570c579 | 09861651617ba0fec089e8b9477439e68398c110, 5eacdb1967378f5e5591cd27a2d8cdee2df1a599, b5e9c09309e18fd9839ad007c238120353ca0cc4, fd94a779020f2ecc8b2607f4c20b34acb1763b9a, 4671bb74bba05fdd4acf670a35758c29e8c97b83, ce93228e2193a17d2c58b656e439bb39fe5c3af8, 44f37ee92fdcd377c41bdf6a31cdd8cc7d4c410e, 2dc0bfd2fe355fb930de63c2f2eb8ced8570c579 |
| Linux/Linuxgeneric | 3.11 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: partitions: aix: bound the pp_count scan to the ppe array aix_partition() reads the physical volume descriptor into a fixed-size struct pvd and then scans its physical-partition-extent array: int numpps = be16_to_cpu(pvd->pp_count); ... for (i = 0; i < numpps; i += 1) { struct ppe *p = pvd->ppe + i; ... lp_ix = be16_to_cpu(p->lp_ix); pvd points at a single kmalloc()'d struct pvd whose ppe[] member holds a fixed ARRAY_SIZE(pvd->ppe) (1016) entries, but the loop runs up to the on-disk pp_count. pp_count is an unvalidated __be16 read straight from the descriptor, so a crafted AIX image with pp_count larger than 1016 drives the loop to read pvd->ppe[i] past the end of the allocation (up to 65535 entries, ~2 MB out of bounds). The partition scan runs without mounting anything, when a block device with a crafted AIX/IBM partition table appears (an attacker-supplied image attached with losetup -P, or a device auto-scanned by udev), via msdos_partition() -> aix_partition(). Clamp the scan to the number of entries the ppe[] array can hold.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <09861651617ba0fec089e8b9477439e68398c110 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <5eacdb1967378f5e5591cd27a2d8cdee2df1a599 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <b5e9c09309e18fd9839ad007c238120353ca0cc4 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <fd94a779020f2ecc8b2607f4c20b34acb1763b9a || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <4671bb74bba05fdd4acf670a35758c29e8c97b83 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <ce93228e2193a17d2c58b656e439bb39fe5c3af8 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <44f37ee92fdcd377c41bdf6a31cdd8cc7d4c410e || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <2dc0bfd2fe355fb930de63c2f2eb8ced8570c579 | 09861651617ba0fec089e8b9477439e68398c110, 5eacdb1967378f5e5591cd27a2d8cdee2df1a599, b5e9c09309e18fd9839ad007c238120353ca0cc4, fd94a779020f2ecc8b2607f4c20b34acb1763b9a, 4671bb74bba05fdd4acf670a35758c29e8c97b83, ce93228e2193a17d2c58b656e439bb39fe5c3af8, 44f37ee92fdcd377c41bdf6a31cdd8cc7d4c410e, 2dc0bfd2fe355fb930de63c2f2eb8ced8570c579 |
| Linux/Linuxgeneric | 3.11 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: partitions: aix: bound the pp_count scan to the ppe array aix_partition() reads the physical volume descriptor into a fixed-size struct pvd and then scans its physical-partition-extent array: int numpps = be16_to_cpu(pvd->pp_count); ... for (i = 0; i < numpps; i += 1) { struct ppe *p = pvd->ppe + i; ... lp_ix = be16_to_cpu(p->lp_ix); pvd points at a single kmalloc()'d struct pvd whose ppe[] member holds a fixed ARRAY_SIZE(pvd->ppe) (1016) entries, but the loop runs up to the on-disk pp_count. pp_count is an unvalidated __be16 read straight from the descriptor, so a crafted AIX image with pp_count larger than 1016 drives the loop to read pvd->ppe[i] past the end of the allocation (up to 65535 entries, ~2 MB out of bounds). The partition scan runs without mounting anything, when a block device with a crafted AIX/IBM partition table appears (an attacker-supplied image attached with losetup -P, or a device auto-scanned by udev), via msdos_partition() -> aix_partition(). Clamp the scan to the number of entries the ppe[] array can hold.
Quoted source text, attributed separately from HOL analysis.