Answer in brief
CVE-2026-64323 records a Unknown severity vulnerability in udf: validate VAT header length against the VAT inode size. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64323 records a Unknown severity vulnerability in udf: validate VAT header length against the VAT inode size. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fa5e08156335d0687c85b4e724db9448fb166601 <0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934 || >=fa5e08156335d0687c85b4e724db9448fb166601 <883962731420ec271ed8c1cd76524f4b17faa982 || >=fa5e08156335d0687c85b4e724db9448fb166601 <2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63 || >=fa5e08156335d0687c85b4e724db9448fb166601 <bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb || >=fa5e08156335d0687c85b4e724db9448fb166601 <55287a3555ff0515b3aff181d2c08c0462a41709 || >=fa5e08156335d0687c85b4e724db9448fb166601 <e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad || >=fa5e08156335d0687c85b4e724db9448fb166601 <74580fdf022909e184223cacc364feb826982d96 || >=fa5e08156335d0687c85b4e724db9448fb166601 <d8202786b3d75125c84ebc4de6d946f92fde0ee8 | 0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934, 883962731420ec271ed8c1cd76524f4b17faa982, 2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63, bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb, 55287a3555ff0515b3aff181d2c08c0462a41709, e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad, 74580fdf022909e184223cacc364feb826982d96, d8202786b3d75125c84ebc4de6d946f92fde0ee8 |
| Linux/Linuxgeneric | 2.6.26 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it against the VAT inode size: map->s_type_specific.s_virtual.s_start_offset = le16_to_cpu(vat20->lengthHeader); map->s_type_specific.s_virtual.s_num_entries = (sbi->s_vat_inode->i_size - map->s_type_specific.s_virtual.s_start_offset) >> 2; lengthHeader is a fully attacker-controlled 16-bit value. If it exceeds the VAT inode size, the s_num_entries subtraction underflows to a huge count, which defeats the "block > s_num_entries" bound in udf_get_pblock_virt15(); and on the ICB-inline path that function reads ((__le32 *)(iinfo->i_data + s_start_offset))[block] so a large s_start_offset indexes past the inode's in-ICB data. Mounting a crafted UDF image with a virtual (VAT) partition then triggers an out-of-bounds read. Reject a VAT whose header length does not leave room for at least one entry within the VAT inode.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fa5e08156335d0687c85b4e724db9448fb166601 <0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934 || >=fa5e08156335d0687c85b4e724db9448fb166601 <883962731420ec271ed8c1cd76524f4b17faa982 || >=fa5e08156335d0687c85b4e724db9448fb166601 <2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63 || >=fa5e08156335d0687c85b4e724db9448fb166601 <bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb || >=fa5e08156335d0687c85b4e724db9448fb166601 <55287a3555ff0515b3aff181d2c08c0462a41709 || >=fa5e08156335d0687c85b4e724db9448fb166601 <e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad || >=fa5e08156335d0687c85b4e724db9448fb166601 <74580fdf022909e184223cacc364feb826982d96 || >=fa5e08156335d0687c85b4e724db9448fb166601 <d8202786b3d75125c84ebc4de6d946f92fde0ee8 | 0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934, 883962731420ec271ed8c1cd76524f4b17faa982, 2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63, bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb, 55287a3555ff0515b3aff181d2c08c0462a41709, e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad, 74580fdf022909e184223cacc364feb826982d96, d8202786b3d75125c84ebc4de6d946f92fde0ee8 |
| Linux/Linuxgeneric | 2.6.26 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it against the VAT inode size: map->s_type_specific.s_virtual.s_start_offset = le16_to_cpu(vat20->lengthHeader); map->s_type_specific.s_virtual.s_num_entries = (sbi->s_vat_inode->i_size - map->s_type_specific.s_virtual.s_start_offset) >> 2; lengthHeader is a fully attacker-controlled 16-bit value. If it exceeds the VAT inode size, the s_num_entries subtraction underflows to a huge count, which defeats the "block > s_num_entries" bound in udf_get_pblock_virt15(); and on the ICB-inline path that function reads ((__le32 *)(iinfo->i_data + s_start_offset))[block] so a large s_start_offset indexes past the inode's in-ICB data. Mounting a crafted UDF image with a virtual (VAT) partition then triggers an out-of-bounds read. Reject a VAT whose header length does not leave room for at least one entry within the VAT inode.
Quoted source text, attributed separately from HOL analysis.