CVE-2026-93828

Summary

In the Linux kernel, the following vulnerability has been resolved:

exfat: fix handling of damaged volume in exfat_create_upcase_table()

When the size of the upcase table is set to zero in the dentry for any reason(e.g. corrupted media or misbehaving device), an integer overflow causes the module to loop indefinitely.

If the size of the upcase table is read zero, do not attempt to load the table. Instead, fallback to loading the default upcase table. If the size of the upcase table is zero or no upcase table is found, raise exfat_fs_error() to mark the volume read-only.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux370e812b3ec190fa492c9fd5a80c38b086d105c0 < 60ace93811609e4dd883e9de5fb4462ed834160aaffected
LinuxLinux370e812b3ec190fa492c9fd5a80c38b086d105c0 < 2cc0b612343638057ef321ce735201a7c2f52f25affected
LinuxLinux370e812b3ec190fa492c9fd5a80c38b086d105c0 < 20dd3185d13865214ff25b0bf7b931e8d73be1acaffected
LinuxLinux5.7affected
LinuxLinux0 < 5.7unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References