From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 13EB23921DC for ; Sun, 19 Jul 2026 12:04:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784462691; cv=none; b=aV0lCtawuRSjbIcl4L3iA3444UY6M0cv7BMBL+askP9cnZq386rqt3CyMLPIkWS+FAw6aUAlnk83vz1PcxUw2Dz+V+wcUB0MMELolWdkL5cAQ65aRnqbLQTHUWBw7jDhK9lYmUoc7EK0RgFPvunH4o2apiSdC8Ac940Vk76UbIM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784462691; c=relaxed/simple; bh=eUpBAJPkYbX1j8uRPvYqhAvg39gb1H15LjMKydOnsX8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=L0xgZsrBXCatJkTCVOHauviNglIjRpfqckO87M3+4GhNB/NQclh3w/9r47zNM/s+u5W8c/odUaeXFa41569anUZD3/X8BQsQZ/B/tD0akPxlMKsU1dphQvzOoGdXyzFdUxtTGzJJx/ovNZ8NiQHqkJox76Hbysc9z3o41mowuTo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=jkoCCSs9; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="jkoCCSs9" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7754F1F000E9; Sun, 19 Jul 2026 12:04:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1784462690; bh=Qzioif+5H7Vr+T604Skc463WSgB7KKQum0PojbJRfbE=; h=From:To:Cc:Subject:Date:Reply-To; b=jkoCCSs9HVnvK2HvTdAjj+KRcLD4m0K9fS8UWjsMW2moSYt/TMe14Hnoe5hRklxSj c02wkC5sZqLiP971FJXwNkCet+IsPk6kAtfXQkWIdKxdObKlK6TsmGQ4j4UYjvdUCf 7BrYYuk6Tkwmq0eyBshjpfZbCEp6D8EEnj32UTCs= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() Date: Sun, 19 Jul 2026 14:02:25 +0200 Message-ID: <2026071902-CVE-2026-63808-263b@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4772; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=n+ld7fJgvhEZqfsfkr4+jr7I1XUTcCdiYHBdyGMB/TU=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkxe3avXhPv9ll+Rr9zRHTw7fBvdV/ehbxcH6F98Oazq XMPyf137IhlYRBkYpAVU2T5so3n6P6KQ4pehranYeawMoEMYeDiFICJ3HBmmKf8xHG+i2hwnfLz RYsTBWSWHAmu28owV0ju+XIz83M7L/+ybuGxjjOeeDTkMQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the fall-through TYPE_EXTEND branch reads the directory entry through ep (which points into bh->b_data): brelse(bh); if (entry_type == TYPE_EXTEND) { ... len = exfat_extract_uni_name(ep, entry_uniname); ... } After brelse() drops our reference, nothing guarantees that the underlying page backing bh->b_data remains valid for the subsequent exfat_extract_uni_name() read. This is the same pattern fixed in commit fc961522ddbd ("exfat: Fix potential use after free in exfat_load_upcase_table()"). Move brelse(bh) so it runs after ep is no longer dereferenced on each branch. Confirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y + CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image (long filename with same-hash collisions forcing the TYPE_EXTEND path). With a debug-only invalidate_bdev() inserted between brelse(bh) and the ep read to make the stale-deref window deterministic, the unpatched kernel faults: BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0 BUG: unable to handle page fault for address: ffff88801a5fa0c2 Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0 With this patch applied, the same instrumented harness completes cleanly under the same sanitizer stack. I have not reproduced a crash on an uninstrumented kernel under ordinary reclaim; the instrumented A/B establishes the lifetime violation and that the patch closes it, not an unaided triggerability claim. The Linux kernel CVE team has assigned CVE-2026-63808 to this issue. Affected and fixed versions =========================== Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 5.10.260 with commit e6f1a11cfb808441a43ffae9b476cc135732cd27 Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 5.15.211 with commit e48f413c2815787b8cade2795e194e3c4cd782ef Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 6.1.177 with commit 06c4e1e9967d332ac33ba38b7819851089ff9359 Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 6.6.144 with commit 8e0abc17fbd7e305802e84fe98b4950d50f9c433 Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 6.12.95 with commit 4d101016d5e587f820b3ae2d5bb6770d86342649 Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 6.18.38 with commit adfacfbaeae2cb760f492357cc36b41f84ef7f86 Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 7.1.3 with commit 708b97e792945d3e4653939fd3405d71a61ad065 Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 7.2-rc1 with commit 3f5f8ee9917cc2b9076ac533492d8a200edcabb8 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-63808 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/exfat/dir.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/e6f1a11cfb808441a43ffae9b476cc135732cd27 https://git.kernel.org/stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef https://git.kernel.org/stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359 https://git.kernel.org/stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433 https://git.kernel.org/stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649 https://git.kernel.org/stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86 https://git.kernel.org/stable/c/708b97e792945d3e4653939fd3405d71a61ad065 https://git.kernel.org/stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8