Back to overview

CVE-2026-53369

Description
In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. Reject such descriptors instead of silently accepting them. A legitimate single-block descriptor should never have a CRC length that exceeds the block.

Metadata

CVE ID
CVE-2026-53369
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-07-19 09:10 UTC
Last updated
2026-07-19 09:10 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 832ab4a882dc9b3c0155490d9993642ef545fd22, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7d1b6adbf90df6c8941090d5646fbeca25ba9770, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3dede76d525919bb966f9213e131af685de5ff99, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 50dfaf4a027742b4fcdc3e9305e7199ece9bc6a6 …
Linux Linux 2.6.12, 0 < 2.6.12, 5.10.258 ≤ 5.10.*, 5.15.209 ≤ 5.15.* …
Back to overview