Description
In the Linux kernel, the following vulnerability has been resolved:

udf: reject VAT indexes equal to the entry count

UDF 1.50 virtual partition mapping uses the VAT as an array of physical
block mappings. s_num_entries stores the number of entries in that array,
not the highest valid index. The valid VAT indexes are therefore below
s_num_entries.

udf_get_pblock_virt15() currently rejects only indexes greater than
s_num_entries. A crafted image can request index s_num_entries, pass the
bounds check, and make the kernel read one entry past the allocated VAT table.

Change the check to reject block >= s_num_entries, so the count is handled as
an exclusive upper bound.

A crafted UDF image reproduced this on origin/master commit
0e35b9b6ec0ffcc5e23cbdec09f5c622ad532b53 with a KASAN slab-out-of-bounds
report in udf_get_pblock_virt15().

Trail of Bits has a reproducer that triggers kernel panic demonstrating the bug, and can share it if needed.
Published: 2026-09-11
Score: 4.0 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Out‑of‑Bounds Read / Denial of Service
Action: Apply Patch
AI Analysis

Impact

The flaw exists in the UDF 1.50 virtual partition handling in the Linux kernel. During processing of a UDF filesystem, the routine that maps virtual block addresses to physical blocks accepts an index that is equal to the number of entries in the Virtual Address Table. This off‑by‑one error lets a crafted UDF image read one element beyond the table’s bounds, causing a KASAN slab‑out‑of‑bounds error and potentially a kernel panic. The bug corresponds to CWE‑1285 – Off‑by‑One Error – and could leak memory contents and force the system to reboot, but the current public evidence indicates a denial‑of‑service outcome rather than remote code execution.

Affected Systems

Any distribution that incorporates a Linux kernel containing UDF 1.50 virtual partition support before the fix, identified by the kernel commit 0e35b9b6. This includes a broad set of consumer and enterprise Linux releases whose kernels have not yet been updated with the boundary‑check change.

Risk and Exploitability

The fixed CVSS score is 4.0, and the EPSS score is less than 1%, showing a low likelihood of exploitation. It is not listed in CISA KEV. The likely attack vector, based on the description, is local: an attacker must supply a malicious UDF image that the kernel processes, such as via removable media or an untrusted filesystem image. The vulnerability can lead to a kernel panic and system denial of service, with no publicly documented code‑execution path.

Generated by OpenCVE AI on September 15, 2026 at 22:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the upstream kernel patch that changes the bounds check to reject indexes greater than or equal to the entry count, or upgrade to a distribution kernel that includes commit 0e35b9b6.
  • If UDF support is unnecessary, temporarily disable the UDF filesystem module to avoid triggering the flaw.
  • Monitor kernel logs for UDF‑related panics or KASAN messages and restrict mounting of untrusted removable media until the patch is in place.

Generated by OpenCVE AI on September 15, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1285
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: udf: reject VAT indexes equal to the entry count UDF 1.50 virtual partition mapping uses the VAT as an array of physical block mappings. s_num_entries stores the number of entries in that array, not the highest valid index. The valid VAT indexes are therefore below s_num_entries. udf_get_pblock_virt15() currently rejects only indexes greater than s_num_entries. A crafted image can request index s_num_entries, pass the bounds check, and make the kernel read one entry past the allocated VAT table. Change the check to reject block >= s_num_entries, so the count is handled as an exclusive upper bound. A crafted UDF image reproduced this on origin/master commit 0e35b9b6ec0ffcc5e23cbdec09f5c622ad532b53 with a KASAN slab-out-of-bounds report in udf_get_pblock_virt15(). Trail of Bits has a reproducer that triggers kernel panic demonstrating the bug, and can share it if needed.
Title udf: reject VAT indexes equal to the entry count
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:41.807Z

Reserved: 2026-09-11T19:38:34.719Z

Link: CVE-2026-89525

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:35.263

Modified: 2026-09-14T13:19:08.273

Link: CVE-2026-89525

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:06Z

Links: CVE-2026-89525 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:30:15Z

Weaknesses
  • CWE-1285

    Improper Validation of Specified Index, Position, or Offset in Input