Impact
The UDF driver incorrectly treats the sparing table length field as a byte count during validation, while later processing interprets it as a count of eight‑byte sparingEntry structures. This mismatch allows the driver to read beyond the filesystem block boundary during the sparing table walk and to write beyond the block when relocating blocks, resulting in out‑of‑bounds memory accesses that corrupt kernel memory.
Affected Systems
All Linux kernel releases that have not yet incorporated the patch for the UDF driver are affected. The CNA and CPE data cover the kernel as a whole, including versions 3.5 and prior releases, meaning any kernel without the fix for this specific logic flaw is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score of < 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery of a malicious UDF image that triggers the fault while the kernel parses the sparing table; this is inferred from the description of how the bug manifests during UDF image handling.
OpenCVE Enrichment
Debian DLA
Ubuntu USN