SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-53369

HIGH · CVSS 8.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of Universal Disk Format (UDF) images, specifically allowing crafted images to bypass CRC validation by using an oversized descriptor length. This flaw can lead to the acceptance of potentially malicious data, compromising system integrity and security. Organizations utilizing Linux systems, particularly those handling UDF images, should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-53369
Severity
HIGH
CVSS
8.4
EPSS
0.15%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. Reject such descriptors instead of silently accepting them. A legitimate single-block descriptor should never have a CRC length that exceeds the block.

Related CVEs

Other vulnerabilities affecting the same vendor(s)