Ad

CVE-2026-89525

NONE EPSS 0.18%
Обновлено 14 сентября 2026
Linux
Параметр Значение
Поставщик Linux
Публичный эксплойт Нет

В ядре Linux устранена следующая уязвимость: udf: отклонить индексы НДС, равные количеству записей Сопоставление виртуальных разделов UDF 1.50 использует НДС как массив физических разделов. сопоставления блоков. s_num_entries хранит количество записей в этом массиве, не самый высокий действительный индекс. Таким образом, действительные индексы НДС ниже. s_num_entries. udf_get_pblock_virt15() в настоящее время отклоняет только индексы, превышающие s_num_entries. Созданное изображение может запросить индекс s_num_entries, передать проверка границ и заставить ядро прочитать одну запись за выделенной таблицей НДС.

Измените проверку на отклонение блока >= s_num_entries, чтобы счетчик обрабатывался как исключительная верхняя граница. Созданный образ UDF воспроизвел это при исходной/главной фиксации. 0e35b9b6ec0ffcc5e23cbdec09f5c622ad532b53 с плитой KASAN за пределами поля отчет в udf_get_pblock_virt15(). У Trail of Bits есть воспроизводитель, который вызывает панику ядра, демонстрируя ошибку, и может поделиться ею при необходимости.

Показать оригинальное описание (EN)

In the Linux kernel, the following vulnerability has been resolved: udf: reject VAT indexes equal to the entry count UDF 1.50 virtual partition mapping uses the VAT as an array of physical block mappings. s_num_entries stores the number of entries in that array, not the highest valid index. The valid VAT indexes are therefore below s_num_entries. udf_get_pblock_virt15() currently rejects only indexes greater than s_num_entries. A crafted image can request index s_num_entries, pass the bounds check, and make the kernel read one entry past the allocated VAT table. Change the check to reject block >= s_num_entries, so the count is handled as an exclusive upper bound. A crafted UDF image reproduced this on origin/master commit 0e35b9b6ec0ffcc5e23cbdec09f5c622ad532b53 with a KASAN slab-out-of-bounds report in udf_get_pblock_virt15(). Trail of Bits has a reproducer that triggers kernel panic demonstrating the bug, and can share it if needed.