CVE-2026-53369 (GCVE-0-2026-53369)
Vulnerability from cvelistv5
Published
2026-07-19 09:10
Modified
2026-08-05 12:35
Summary
In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. Reject such descriptors instead of silently accepting them. A legitimate single-block descriptor should never have a CRC length that exceeds the block.
Impacted products
Vendor Product Version
Linux Linux Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/udf/misc.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "832ab4a882dc9b3c0155490d9993642ef545fd22",
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "versionType": "git"
            },
            {
              "lessThan": "7d1b6adbf90df6c8941090d5646fbeca25ba9770",
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "versionType": "git"
            },
            {
              "lessThan": "3dede76d525919bb966f9213e131af685de5ff99",
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "versionType": "git"
            },
            {
              "lessThan": "50dfaf4a027742b4fcdc3e9305e7199ece9bc6a6",
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "versionType": "git"
            },
            {
              "lessThan": "31605bbe94557bff721eaf041001169d44ac6f98",
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "versionType": "git"
            },
            {
              "lessThan": "1873eb81c65d3f849418d7386baa39c439c9fc38",
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "versionType": "git"
            },
            {
              "lessThan": "fdb26e628d2a211a23815d375bd33bdf863344e2",
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "versionType": "git"
            },
            {
              "lessThan": "55d41b0a20128e86b9e960dd2e3f0a2d69a18df7",
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/udf/misc.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.12"
            },
            {
              "lessThan": "2.6.12",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.258",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.209",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.140",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.88",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.30",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.258",
                  "versionStartIncluding": "2.6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.209",
                  "versionStartIncluding": "2.6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.175",
                  "versionStartIncluding": "2.6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.140",
                  "versionStartIncluding": "2.6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.88",
                  "versionStartIncluding": "2.6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.30",
                  "versionStartIncluding": "2.6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.7",
                  "versionStartIncluding": "2.6.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "2.6.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: reject descriptors with oversized CRC length\n\nudf_read_tagged() skips CRC verification when descCRCLength +\nsizeof(struct tag) exceeds the block size.  A crafted UDF image can\nset descCRCLength to an oversized value to bypass CRC validation\nentirely; the descriptor is then accepted based solely on the 8-bit\ntag checksum, which is trivially recomputable.\n\nReject such descriptors instead of silently accepting them.  A\nlegitimate single-block descriptor should never have a CRC length that\nexceeds the block."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable `udf_read_tagged()` runs in kernel UDF metadata parsing reached via the `mount()`/`fsopen` path through `get_tree_bdev()` \u2192 `udf_fill_super()` and on later VFS inode lookups via `udf_read_ptagged()`. UDF is a block-device filesystem (DVD/USB/loop), not a wire protocol parser like nfsd or ksmbd; exploitation requires supplying a crafted image on a block device the kernel reads.\nAC:L - Triggering the flaw is reliable: set `descCRCLength` so `descCRCLength + sizeof(struct tag)` exceeds the block size, recompute the trivial 8-bit `tagChecksum` over the 16-byte tag header, and the descriptor is accepted with arbitrary body content. No races or victim-specific memory layout are required.\nPR:N - No target-system account is needed in the highest-impact scenario: a crafted UDF USB/DVD inserted into a kiosk, automotive head unit, or shared workstation is auto-mounted by udev/systemd as root. An unprivileged local attacker with user-namespace `CAP_SYS_ADMIN` can also mount a loop-backed crafted image (PR:L), but PR:N is chosen when uncertain.\nUI:N - When the attacker mounts their own crafted image (including via user namespace) or relies on automated mounting of removable media, no additional victim interaction beyond the attacker\u0027s own action is required. UI:R applies only to purely victim-initiated manual mounts.\nS:U - Exploitation stays within kernel host context parsing attacker-controlled filesystem metadata; it does not cross a VM, container, or IOMMU security boundary by itself, though it can enable local privilege escalation.\nC:H - Bypassing descriptor CRC lets an attacker forge partition descriptors, logical volume descriptors, and file entries that would otherwise be rejected, directing `udf_get_pblock()`/`sb_bread()` to attacker-chosen locations on the backing block device and feeding corrupted metadata into later parsers. Similar UDF crafted-image bugs have produced kernel out-of-bounds reads; this integrity bypass is a plausible path to arbitrary kernel memory disclosure.\nI:H - Forged descriptors can supply malicious partition maps, extent locations, and inode allocation metadata that downstream UDF code treats as validated, enabling arbitrary block-device writes on read-write mounts and heap/metadata corruption exploitable for control-flow hijacking. When uncertain between limited and arbitrary impact, the higher severity applies.\nA:H - Accepting CRC-bypassed malformed descriptors during mount or inode load can cause kernel oops/panic through inconsistent metadata in allocation, directory, and extent handling paths. Even when full exploitation is not achieved, corrupted descriptor processing commonly crashes the kernel."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:35:16.376Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/832ab4a882dc9b3c0155490d9993642ef545fd22"
        },
        {
          "url": "https://git.kernel.org/stable/c/7d1b6adbf90df6c8941090d5646fbeca25ba9770"
        },
        {
          "url": "https://git.kernel.org/stable/c/3dede76d525919bb966f9213e131af685de5ff99"
        },
        {
          "url": "https://git.kernel.org/stable/c/50dfaf4a027742b4fcdc3e9305e7199ece9bc6a6"
        },
        {
          "url": "https://git.kernel.org/stable/c/31605bbe94557bff721eaf041001169d44ac6f98"
        },
        {
          "url": "https://git.kernel.org/stable/c/1873eb81c65d3f849418d7386baa39c439c9fc38"
        },
        {
          "url": "https://git.kernel.org/stable/c/fdb26e628d2a211a23815d375bd33bdf863344e2"
        },
        {
          "url": "https://git.kernel.org/stable/c/55d41b0a20128e86b9e960dd2e3f0a2d69a18df7"
        }
      ],
      "title": "udf: reject descriptors with oversized CRC length",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-53369",
    "datePublished": "2026-07-19T09:10:30.283Z",
    "dateReserved": "2026-06-09T07:44:35.401Z",
    "dateUpdated": "2026-08-05T12:35:16.376Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…