Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-63808

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
19/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> exfat: fix potential use-after-free in exfat_find_dir_entry()<br /> <br /> In exfat_find_dir_entry(), the buffer_head obtained from<br /> exfat_get_dentry() is released with brelse(bh) before the fall-through<br /> TYPE_EXTEND branch reads the directory entry through ep (which points<br /> into bh-&gt;b_data):<br /> <br /> brelse(bh);<br /> if (entry_type == TYPE_EXTEND) {<br /> ...<br /> len = exfat_extract_uni_name(ep, entry_uniname);<br /> ...<br /> }<br /> <br /> After brelse() drops our reference, nothing guarantees that the<br /> underlying page backing bh-&gt;b_data remains valid for the subsequent<br /> exfat_extract_uni_name() read. This is the same pattern fixed in<br /> commit fc961522ddbd ("exfat: Fix potential use after free in<br /> exfat_load_upcase_table()").<br /> <br /> Move brelse(bh) so it runs after ep is no longer dereferenced on<br /> each branch.<br /> <br /> Confirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y<br /> + CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image<br /> (long filename with same-hash collisions forcing the TYPE_EXTEND path).<br /> With a debug-only invalidate_bdev() inserted between brelse(bh) and<br /> the ep read to make the stale-deref window deterministic, the<br /> unpatched kernel faults:<br /> <br /> BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0<br /> BUG: unable to handle page fault for address: ffff88801a5fa0c2<br /> Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI<br /> RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0<br /> <br /> With this patch applied, the same instrumented harness completes<br /> cleanly under the same sanitizer stack. I have not reproduced a<br /> crash on an uninstrumented kernel under ordinary reclaim; the<br /> instrumented A/B establishes the lifetime violation and that the<br /> patch closes it, not an unaided triggerability claim.

Impacto