SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-89525

UNKNOWN · CVSS N/A EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of UDF 1.50 virtual partition mapping, specifically in the validation of VAT indexes, which can lead to out-of-bounds memory access. An attacker can exploit this flaw by crafting a UDF image that requests an invalid index, potentially causing a kernel panic and compromising system stability. Organizations utilizing Linux systems, particularly those relying on UDF for file system management, should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-89525
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%
Linux F5

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: udf: reject VAT indexes equal to the entry count UDF 1.50 virtual partition mapping uses the VAT as an array of physical block mappings. s_num_entries stores the number of entries in that array, not the highest valid index. The valid VAT indexes are therefore below s_num_entries. udf_get_pblock_virt15() currently rejects only indexes greater than s_num_entries. A crafted image can request index s_num_entries, pass the bounds check, and make the kernel read one entry past the allocated VAT table. Change the check to reject block >= s_num_entries, so the count is handled as an exclusive upper bound. A crafted UDF image reproduced this on origin/master commit 0e35b9b6ec0ffcc5e23cbdec09f5c622ad532b53 with a KASAN slab-out-of-bounds report in udf_get_pblock_virt15(). Trail of Bits has a reproducer that triggers kernel panic demonstrating the bug, and can share it if needed.