CVE-2026-64432
CVE CVE-2026-64432EUVD EUVD-2026-48776Veröffentlicht 2026-07-25T08:51:07.000ZZuletzt geändert 2026-08-05T12:41:56.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns In the analysis pass of $LogFile journal replay, log_replay() copies LCNs from each action log record into an existing Dirty Page Table (DPT) entry without bounding the destination index. A crafted NTFS image with DPT entry lcns_follow=1 and an action log record with lcns_follow=2 produces a kernel slab out-of-bounds write at mount time: BUG: KASAN: slab-out-of-bounds in log_replay+0x654c/0xdb60 Write of size 8 at addr ffff8880095e1040 by task mount Two attacker-controlled fields can drive j+i past the allocated page_lcns[] array: 1. dp->lcns_follow (capacity) can be smaller than lrh->lcns_follow. 2. lrh->target_vcn may be smaller than dp->vcn, making the u64 subtraction wrap to a huge size_t. Validate target VCN delta and per-record LCN count against the DPT entry capacity, bail via the existing out: cleanup label with -EINVAL. This mirrors the bounds-check pattern added in commit b2bc7c44ed17 ("fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot") and commit 0ca0485e4b2e ("fs/ntfs3: validate rec->used in journal-replay file record check").
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux b46acd6a6a627d876898e1c84d3f84902264b445 <57382ec6ac63b63dce2789e835fded28b698ae79; b46acd6a6a627d876898e1c84d3f84902264b445 <cf28fc1658463d768657cf1c27a83980d4ba7ef2; patch: 6.6.145; patch: 5.15.212; patch: 7.1.4; patch: 0; patch: 6.18.39; 5.15; patch: 6.1.178; patch: 6.12.96; b46acd6a6a627d876898e1c84d3f84902264b445 <f433acc85b86f327d03ba8b03a33c105c51053de; b46acd6a6a627d876898e1c84d3f84902264b445 <964c3fae1dfc49dde5468eace940f199cda234e9; b46acd6a6a627d876898e1c84d3f84902264b445 <c6f9e804f73ef809529865fbc7256dd189ff8c33; patch: 7.2-rc1; b46acd6a6a627d876898e1c84d3f84902264b445 <946046841013ebac8492ef49651c53638d7a9a6a; b46acd6a6a627d876898e1c84d3f84902264b445 <3aa96956ca2200674e2a8f9c23ec6ecd45e5010f
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.