Dismissed
(max. allowed matches exceeded)
Permalink
CVE-2026-53369
8.4 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created & dismissed (max. allowed matches exceeded) suggestion
udf: reject descriptors with oversized CRC length
In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. Reject such descriptors instead of silently accepting them. A legitimate single-block descriptor should never have a CRC length that exceeds the block.
References
Affected products
Linux
- =<5.10.*
- <1873eb81c65d3f849418d7386baa39c439c9fc38
- =<6.18.*
- <50dfaf4a027742b4fcdc3e9305e7199ece9bc6a6
- <31605bbe94557bff721eaf041001169d44ac6f98
- =<7.0.*
- =<5.15.*
- =<6.12.*
- <2.6.12
- <55d41b0a20128e86b9e960dd2e3f0a2d69a18df7
- <7d1b6adbf90df6c8941090d5646fbeca25ba9770
- =<6.1.*
- <832ab4a882dc9b3c0155490d9993642ef545fd22
- =<6.6.*
- ==2.6.12
- =<*
- <3dede76d525919bb966f9213e131af685de5ff99
- <fdb26e628d2a211a23815d375bd33bdf863344e2