← Retour à la recherche de CVE

CVE-2026-64074

Linux Kernel

Description

In the Linux kernel, the following vulnerability has been resolved: fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap statmount_mnt_idmap() writes one mapping with seq_printf() and then manually advances seq->count to include the NUL separator. If seq_printf() overflows, seq_set_overflow() sets seq->count to seq->size. The manual seq->count++ changes this to seq->size + 1. seq_has_overflowed() then no longer detects the overflow. The corrupted count returns to statmount_string(), which later executes: seq->buf[seq->count++] = -\0-; This causes a 1-byte NULL out-of-bounds write on the dynamically allocated seq buffer. Fix this by checking for overflow immediately after seq_printf().

CVSS 7.8EPSS 0.127%Risque 0.79
Voir la source
Publication
2026-07-19 16:17:48
Versions concernées
unknown
Type
Système d’exploitation
Dernière modification
2026-07-30 14:59:47
Vecteur
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H