CVE-2026-63808

Source
https://cve.org/CVERecord?id=CVE-2026-63808
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63808.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63808
Downstream
Published
2026-07-19T12:02:11.323Z
Modified
2026-07-22T05:30:03.634108748Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
exfat: fix potential use-after-free in exfat_find_dir_entry()
Details

In the Linux kernel, the following vulnerability has been resolved:

exfat: fix potential use-after-free in exfatfinddir_entry()

In exfatfinddirentry(), the bufferhead obtained from exfatgetdentry() is released with brelse(bh) before the fall-through TYPEEXTEND branch reads the directory entry through ep (which points into bh->bdata):

brelse(bh);
if (entry_type == TYPE_EXTEND) {
    ...
    len = exfat_extract_uni_name(ep, entry_uniname);
    ...
}

After brelse() drops our reference, nothing guarantees that the underlying page backing bh->bdata remains valid for the subsequent exfatextractuniname() read. This is the same pattern fixed in commit fc961522ddbd ("exfat: Fix potential use after free in exfatloadupcase_table()").

Move brelse(bh) so it runs after ep is no longer dereferenced on each branch.

Confirmed on QEMU x8664 with CONFIGKASAN=y + CONFIGDEBUGPAGEALLOC=y + CONFIGPAGEPOISONING=y on linux-next, using a crafted exFAT image (long filename with same-hash collisions forcing the TYPEEXTEND path). With a debug-only invalidatebdev() inserted between brelse(bh) and the ep read to make the stale-deref window deterministic, the unpatched kernel faults:

BUG: KASAN: use-after-free in exfatfinddirentry+0x133b/0x15a0 BUG: unable to handle page fault for address: ffff88801a5fa0c2 Oops: 0000 [#1] SMP DEBUGPAGEALLOC KASAN NOPTI RIP: 0010:exfatfinddir_entry+0x1188/0x15a0

With this patch applied, the same instrumented harness completes cleanly under the same sanitizer stack. I have not reproduced a crash on an uninstrumented kernel under ordinary reclaim; the instrumented A/B establishes the lifetime violation and that the patch closes it, not an unaided triggerability claim.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63808.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ca06197382bde0a3bc20215595d1c9ce20c6e341
Fixed
e6f1a11cfb808441a43ffae9b476cc135732cd27
Fixed
e48f413c2815787b8cade2795e194e3c4cd782ef
Fixed
06c4e1e9967d332ac33ba38b7819851089ff9359
Fixed
8e0abc17fbd7e305802e84fe98b4950d50f9c433
Fixed
4d101016d5e587f820b3ae2d5bb6770d86342649
Fixed
adfacfbaeae2cb760f492357cc36b41f84ef7f86
Fixed
708b97e792945d3e4653939fd3405d71a61ad065
Fixed
3f5f8ee9917cc2b9076ac533492d8a200edcabb8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63808.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
5.10.260
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.211
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.177
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.144
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.95
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.38
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63808.json"