Description
In the Linux kernel, the following vulnerability has been resolved:

UDF symlink pathComponent header OOB read

udf_symlink_filler() can enter udf_pc_to_char() with a partial pathComponent header.

Validate that enough input remains for a complete pathComponent header
before accessing it. Reject malformed symlink data that would otherwise
make udf_pc_to_char() perform an out-of-bounds read.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Out‑of‑Bounds Read
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs when the Linux kernel processes a UDF symlink containing a partially‑specified pathComponent header. The udf_symlink_filler function passes this incomplete header to udf_pc_to_char without verifying that a complete header remains in the buffer. This causes an out‑of‑bounds read of kernel memory, potentially exposing sensitive data. The weakness is an input validation flaw that can be classified as a CWE‑839 scenario.

Affected Systems

All Linux systems that use the kernel’s UDF file‑system support are affected. The specific kernel versions are not enumerated in the data, so any system with the UDF module present prior to the rapid patch should be considered vulnerable until the fix is applied.

Risk and Exploitability

The EPSS score is indicated as < 1 %, implying a very low probability of exploitation today. The vulnerability is not listed in CISA’s KEV catalog. No exploit is publicly known. The attacker would need to supply a crafted UDF volume containing a malformed symlink, which could be achieved on systems that mount external media or allow local file system writes. The risk is primarily for confidentiality, with no direct denial of service or privilege escalation indicated. The absence of a CVSS score limits the quantitative assessment, but the nature of the OOB read still warrants prompt patching.

Generated by OpenCVE AI on September 19, 2026 at 06:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the fix for udf_pc_to_char input validation.
  • If a kernel update is not immediately possible, disable or unload the udf kernel module and prevent mounting of UDF file systems until a patch is available.
  • Monitor system logs for warning or error messages related to udf_symlink_filler failures and audit UDF volumes for malformed symlinks.

Generated by OpenCVE AI on September 19, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-839

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: UDF symlink pathComponent header OOB read udf_symlink_filler() can enter udf_pc_to_char() with a partial pathComponent header. Validate that enough input remains for a complete pathComponent header before accessing it. Reject malformed symlink data that would otherwise make udf_pc_to_char() perform an out-of-bounds read.
Title UDF symlink pathComponent header OOB read
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:43.779Z

Reserved: 2026-09-17T15:57:05.659Z

Link: CVE-2026-93055

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:59.060

Modified: 2026-09-17T17:17:59.060

Link: CVE-2026-93055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:15:04Z

Weaknesses
  • CWE-839

    Numeric Range Comparison Without Minimum Check