CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:48:59 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072511-CVE-2026-64322-c496@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

udf: validate sparing table length as an entry count, not a byte count

udf_load_sparable_map() accepts a sparing table when

	sizeof(*st) + le16_to_cpu(st->reallocationTableLen) > sb->s_blocksize

is false, i.e. it treats reallocationTableLen as a number of BYTES that
must fit in the block.  But the table is walked as an array of 8-byte
sparingEntry elements:

	for (i = 0; i < le16_to_cpu(st->reallocationTableLen); i++) {
		struct sparingEntry *entry = &st->mapEntry[i];
		... entry->origLocation ...
	}

in udf_get_pblock_spar15() and udf_relocate_blocks().  A
reallocationTableLen of N therefore passes the check whenever
sizeof(*st) + N <= blocksize, yet the consumers index
sizeof(*st) + N * sizeof(struct sparingEntry) bytes -- up to ~8x the
block.  On a crafted UDF image this is an out-of-bounds read in
udf_get_pblock_spar15(); udf_relocate_blocks() additionally feeds the
same length to udf_update_tag(), whose crc_itu_t() reads far past the
block, and its memmove() through st->mapEntry[] is an out-of-bounds
write.

Validate reallocationTableLen as the entry count it is, with
struct_size().

The Linux kernel CVE team has assigned CVE-2026-64322 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.5 with commit 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 and fixed in 5.10.261 with commit eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e
	Issue introduced in 3.5 with commit 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 and fixed in 5.15.212 with commit 0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9
	Issue introduced in 3.5 with commit 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 and fixed in 6.1.178 with commit 2d726135099313958f8975532a2e15322ff150ce
	Issue introduced in 3.5 with commit 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 and fixed in 6.6.145 with commit 7285276aa50d2839afb5957ffd491ad282dc8f72
	Issue introduced in 3.5 with commit 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 and fixed in 6.12.96 with commit 2a219acb2ce674d99bbd1b7b35ed8c384dac7200
	Issue introduced in 3.5 with commit 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 and fixed in 6.18.39 with commit 04f4599a9efb90992d072a814960edf0cd62805d
	Issue introduced in 3.5 with commit 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 and fixed in 7.1.4 with commit 7f7774b9da0ef17b87bfa238cf966ad0b3376150
	Issue introduced in 3.5 with commit 1df2ae31c724e57be9d7ac00d78db8a5dabdd050 and fixed in 7.2-rc1 with commit 3ec997bd5508e9b25210b5bbec89031629cdb093
	Issue introduced in 2.6.32.60 with commit e240873cb4a9fd18de60a817100a96fe670d4359
	Issue introduced in 2.6.34.14 with commit 9ae30e324a96d0328a575329d7a95a09b3318601
	Issue introduced in 3.0.37 with commit b1c5701ad6b3e5d21d16f65475651cfaaa41e7aa
	Issue introduced in 3.2.23 with commit a9f1af04f086656246f30354fb4564ce3b08c4a0
	Issue introduced in 3.4.5 with commit 4836ee563d65bb492f907cbe267a5761b9693e4d

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64322
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/udf/super.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e
	https://git.kernel.org/stable/c/0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9
	https://git.kernel.org/stable/c/2d726135099313958f8975532a2e15322ff150ce
	https://git.kernel.org/stable/c/7285276aa50d2839afb5957ffd491ad282dc8f72
	https://git.kernel.org/stable/c/2a219acb2ce674d99bbd1b7b35ed8c384dac7200
	https://git.kernel.org/stable/c/04f4599a9efb90992d072a814960edf0cd62805d
	https://git.kernel.org/stable/c/7f7774b9da0ef17b87bfa238cf966ad0b3376150
	https://git.kernel.org/stable/c/3ec997bd5508e9b25210b5bbec89031629cdb093