CVE-2026-64074
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap
statmount_mnt_idmap() writes one mapping with seq_printf() and then manually advances seq->count to include the NUL separator.
If seq_printf() overflows, seq_set_overflow() sets seq->count to seq->size. The manual seq->count++ changes this to seq->size + 1. seq_has_overflowed() then no longer detects the overflow. The corrupted count returns to statmount_string(), which later executes:
seq->buf[seq->count++] = '\0';
This causes a 1-byte NULL out-of-bounds write on the dynamically allocated seq buffer.
Fix this by checking for overflow immediately after seq_printf().
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 37c4a9590e1efcae7749682239fc22a330d2d325 < e37ea2c6f17f273813ea4e8e94c102591d598ce1 | affected |
| Linux | Linux | 37c4a9590e1efcae7749682239fc22a330d2d325 < 93614949dc86f068e3c32c32cf1ee2a2323177a7 | affected |
| Linux | Linux | 37c4a9590e1efcae7749682239fc22a330d2d325 < a3bf0f28d4ba16e1f35f8c983bb04426b87e2a78 | affected |
| Linux | Linux | 6.15 | affected |
| Linux | Linux | 0 < 6.15 | unaffected |
| Linux | Linux | 6.18.34 <= 6.18.* | unaffected |
| Linux | Linux | 7.0.11 <= 7.0.* | unaffected |
| Linux | Linux | 7.1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/e37ea2c6f17f273813ea4e8e94c102591d598ce1
- https://git.kernel.org/stable/c/93614949dc86f068e3c32c32cf1ee2a2323177a7
- https://git.kernel.org/stable/c/a3bf0f28d4ba16e1f35f8c983bb04426b87e2a78
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.