Answer in brief
CVE-2026-64318 records a High severity (CVSS 7.1) vulnerability in partitions: aix: bound the pp_count scan to the ppe array. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <09861651617ba0fec089e8b9477439e68398c110 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <5eacdb1967378f5e5591cd27a2d8cdee2df1a599 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <b5e9c09309e18fd9839ad007c238120353ca0cc4 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <fd94a779020f2ecc8b2607f4c20b34acb1763b9a || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <4671bb74bba05fdd4acf670a35758c29e8c97b83 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <ce93228e2193a17d2c58b656e439bb39fe5c3af8 || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <44f37ee92fdcd377c41bdf6a31cdd8cc7d4c410e || >=6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6 <2dc0bfd2fe355fb930de63c2f2eb8ced8570c579 | 09861651617ba0fec089e8b9477439e68398c110, 5eacdb1967378f5e5591cd27a2d8cdee2df1a599, b5e9c09309e18fd9839ad007c238120353ca0cc4, fd94a779020f2ecc8b2607f4c20b34acb1763b9a, 4671bb74bba05fdd4acf670a35758c29e8c97b83, ce93228e2193a17d2c58b656e439bb39fe5c3af8, 44f37ee92fdcd377c41bdf6a31cdd8cc7d4c410e, 2dc0bfd2fe355fb930de63c2f2eb8ced8570c579 |
| Linux/Linuxgeneric | 3.11 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: partitions: aix: bound the pp_count scan to the ppe array aix_partition() reads the physical volume descriptor into a fixed-size struct pvd and then scans its physical-partition-extent array: int numpps = be16_to_cpu(pvd->pp_count); ... for (i = 0; i < numpps; i += 1) { struct ppe *p = pvd->ppe + i; ... lp_ix = be16_to_cpu(p->lp_ix); pvd points at a single kmalloc()'d struct pvd whose ppe[] member holds a fixed ARRAY_SIZE(pvd->ppe) (1016) entries, but the loop runs up to the on-disk pp_count. pp_count is an unvalidated __be16 read straight from the descriptor, so a crafted AIX image with pp_count larger than 1016 drives the loop to read pvd->ppe[i] past the end of the allocation (up to 65535 entries, ~2 MB out of bounds). The partition scan runs without mounting anything, when a block device with a crafted AIX/IBM partition table appears (an attacker-supplied image attached with losetup -P, or a device auto-scanned by udev), via msdos_partition() -> aix_partition(). Clamp the scan to the number of entries the ppe[] array can hold.
Quoted source text, attributed separately from HOL analysis.