SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64074

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's statmount_mnt_idmap() function, which can lead to a slab out-of-bounds write due to improper handling of sequence buffer overflow. This flaw allows for potential memory corruption, which could be exploited to execute arbitrary code or cause system instability. Organizations utilizing affected Linux kernel versions should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-64074
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap statmount_mnt_idmap() writes one mapping with seq_printf() and then manually advances seq->count to include the NUL separator. If seq_printf() overflows, seq_set_overflow() sets seq->count to seq->size. The manual seq->count++ changes this to seq->size + 1. seq_has_overflowed() then no longer detects the overflow. The corrupted count returns to statmount_string(), which later executes: seq->buf[seq->count++] = '\0'; This causes a 1-byte NULL out-of-bounds write on the dynamically allocated seq buffer. Fix this by checking for overflow immediately after seq_printf().