CVE-2026-93816
🟡 Monitoruj
Błąd w jądrze Linuxa pozwala na odczytanie pamięci poza przydzielonym obszarem podczas konwersji dentry.
CVSS
7.1
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)
In the Linux kernel, the following vulnerability has been resolved: f2fs: validate inline dentry name lengths before conversion Inline dentry conversion copies names out of the inline dentry area before checking that each recorded name length fits in the available filename slots. A corrupted image can therefore make the conversion path read past the inline filename storage while building the regular dentry block. Validate each inline dentry name length against the inline filename area before copying it.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2026-09-24 17:17:15 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:51 UTC |
Referencje
- https://git.kernel.org/stable/c/2ce0bc5853bec7cdc724477a87ea579fde664243 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/4dd81faa63fd54b9ba1a83c304e6d0bd03f1898d (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/6343208fd73f3f2b8044c0922185cd13ff807693 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/6b5552449fc5acb8e6ecf045b46702b29b71165a (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/7caa8a0ae94b132576c2e46e9b4fd4e0f356f373 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/aee4e6de71ca77626c006166ff00f1d01ff990c9 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/cfcd0e49a178b3dac2c0ece656079081dbf5da74 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)