Back to overview

CVE-2026-64074

Description
In the Linux kernel, the following vulnerability has been resolved: fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap statmount_mnt_idmap() writes one mapping with seq_printf() and then manually advances seq->count to include the NUL separator. If seq_printf() overflows, seq_set_overflow() sets seq->count to seq->size. The manual seq->count++ changes this to seq->size + 1. seq_has_overflowed() then no longer detects the overflow. The corrupted count returns to statmount_string(), which later executes: seq->buf[seq->count++] = '\0'; This causes a 1-byte NULL out-of-bounds write on the dynamically allocated seq buffer. Fix this by checking for overflow immediately after seq_printf().

Metadata

CVE ID
CVE-2026-64074
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 15:39 UTC
Last updated
2026-07-19 15:39 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 37c4a9590e1efcae7749682239fc22a330d2d325 < e37ea2c6f17f273813ea4e8e94c102591d598ce1, 37c4a9590e1efcae7749682239fc22a330d2d325 < 93614949dc86f068e3c32c32cf1ee2a2323177a7, 37c4a9590e1efcae7749682239fc22a330d2d325 < a3bf0f28d4ba16e1f35f8c983bb04426b87e2a78
Linux Linux 6.15, 0 < 6.15, 6.18.34 ≤ 6.18.*, 7.0.11 ≤ 7.0.* …
Back to overview