{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-64296",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-07-19T15:36:31.778Z",
        "datePublished": "2026-07-25T08:49:33.847Z",
        "dateUpdated": "2026-08-17T04:52:53.790Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-17T04:52:53.790Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: bound uniname advance in exfat_find_dir_entry()\n\nIn exfat_find_dir_entry(), each TYPE_EXTEND (file name) entry advances the\noutput pointer by a fixed amount while the loop guard only tracks the\naccumulated name length:\n\n\tif (++order == 2)\n\t\tuniname = p_uniname->name;\n\telse\n\t\tuniname += EXFAT_FILE_NAME_LEN;\n\tlen = exfat_extract_uni_name(ep, entry_uniname);\n\tname_len += len;\n\tunichar = *(uniname+len);\n\t*(uniname+len) = 0x0;\n\nuniname grows by EXFAT_FILE_NAME_LEN (15) per name entry, but name_len\ngrows only by the actual extracted length, which is shorter when a name\nfragment contains an early NUL.  The only guard is\n`name_len >= MAX_NAME_LENGTH`, so a crafted directory with many short\nname fragments lets uniname run far past the\np_uniname->name[MAX_NAME_LENGTH + 3] buffer while name_len stays small,\ncausing an out-of-bounds read and write at *(uniname+len).\n\nThe sibling extractor exfat_get_uniname_from_ext_entry() already stops\non a short fragment (the lockstep `len != EXFAT_FILE_NAME_LEN` guard\nadded in commit d42334578eba (\"exfat: check if filename entries exceeds\nmax filename length\")); exfat_find_dir_entry() never got the\nequivalent.  Track the per-entry write offset as a count and reject a\nfragment once the offset, or the offset plus the extracted length, would\nexceed MAX_NAME_LENGTH, before forming the output pointer."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - A crafted exFAT image is reached through local pathname operations such as openat(), which call exfat_lookup(), exfat_find(), and exfat_find_dir_entry(); loop-backed images make physical access unnecessary.\nAC:L - The attacker controls the stream hash, declared name length, extension-entry sequence, and early NUL characters, making the out-of-bounds access deterministic without a race or uncontrollable condition.\nPR:L - Although exFAT cannot be mounted directly from a user namespace, common storage brokers allow an active unprivileged user to mount a loop-backed non-system image. Once mounted, triggering lookup requires only ordinary directory search access and no capability.\nUI:N - The unprivileged attacker can mount the crafted image through such a storage broker and issue the triggering pathname lookup without another user's action.\nS:U - The vulnerable filesystem parser and the affected kernel memory belong to the same security authority; ordinary kernel privilege escalation does not change scope.\nC:H - Crafted entries cause repeated out-of-bounds 16-bit reads across the kernel stack, and filename comparison behavior can provide an oracle over attacker-selected stack locations. Successful control-flow corruption could disclose arbitrary kernel memory.\nI:H - The function writes zero beyond the stack buffer, and the successful-match path can jump to found without restoring the overwritten value. Attacker-selected stack control data or pointers can therefore be corrupted, potentially enabling arbitrary writes or kernel code execution.\nA:H - Zero-length fragments can advance the pointer until it reaches a stack guard page or corrupts control data, causing an oops, panic, or persistent lockup."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/exfat/dir.c"
                    ],
                    "versions": [
                        {
                            "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                            "lessThan": "72a2589d82eb001c94b74bcfe6f9a599bd9bef60",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                            "lessThan": "fae76a94b35ee8c0e2eb6f64caca01d75c6d34e4",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                            "lessThan": "cf85180b8a015029ee147694eaf4e0b3537e9432",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                            "lessThan": "ce4736c1e6c4cfbf1ac409a8c328a0b69546c9a0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                            "lessThan": "727bf7783a2936ffd55c628dddfd69343e511dcf",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                            "lessThan": "33c0b96d7e1672be1de0053786637ea46fb81507",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                            "lessThan": "c8e041c68c0bbb73aa62371ee63947bb6949d8b2",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                            "lessThan": "3a1230e7b043c62737b05a3e9275ca83a43ad20a",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/exfat/dir.c"
                    ],
                    "versions": [
                        {
                            "version": "5.7",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.7",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.261",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.212",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.178",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.145",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.96",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.39",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.4",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "5.10.261"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "5.15.212"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "6.1.178"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "6.6.145"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "6.12.96"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "6.18.39"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "7.1.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "7.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/72a2589d82eb001c94b74bcfe6f9a599bd9bef60"
                },
                {
                    "url": "https://git.kernel.org/stable/c/fae76a94b35ee8c0e2eb6f64caca01d75c6d34e4"
                },
                {
                    "url": "https://git.kernel.org/stable/c/cf85180b8a015029ee147694eaf4e0b3537e9432"
                },
                {
                    "url": "https://git.kernel.org/stable/c/ce4736c1e6c4cfbf1ac409a8c328a0b69546c9a0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/727bf7783a2936ffd55c628dddfd69343e511dcf"
                },
                {
                    "url": "https://git.kernel.org/stable/c/33c0b96d7e1672be1de0053786637ea46fb81507"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c8e041c68c0bbb73aa62371ee63947bb6949d8b2"
                },
                {
                    "url": "https://git.kernel.org/stable/c/3a1230e7b043c62737b05a3e9275ca83a43ad20a"
                }
            ],
            "title": "exfat: bound uniname advance in exfat_find_dir_entry()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}