{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.96-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  udf: validate sparing table length as an entry count, not a byte count  udf_load_sparable_map() accepts a sparing table when  \tsizeof(*st) + le16_to_cpu(st-\u003ereallocationTableLen) \u003e sb-\u003es_blocksize  is false, i.e. it treats reallocationTableLen as a number of BYTES that must fit in the block.  But the table is walked as an array of 8-byte sparingEntry elements:  \tfor (i = 0; i \u003c le16_to_cpu(st-\u003ereallocationTableLen); i++) { \t\tstruct sparingEntry *entry = \u0026st-\u003emapEntry[i]; \t\t... entry-\u003eorigLocation ... \t}  in udf_get_pblock_spar15() and udf_relocate_blocks().  A reallocationTableLen of N therefore passes the check whenever sizeof(*st) + N \u003c= blocksize, yet the consumers index sizeof(*st) + N * sizeof(struct sparingEntry) bytes -- up to ~8x the block.  On a crafted UDF image this is an out-of-bounds read in udf_get_pblock_spar15(); udf_relocate_blocks() additionally feeds the same length to udf_update_tag(), whose crc_itu_t() reads far past the block, and its memmove() through st-\u003emapEntry[] is an out-of-bounds write.  Validate reallocationTableLen as the entry count it is, with struct_size().",
  "id": "DEBIAN-CVE-2026-64322",
  "modified": "2026-09-14T16:47:29.645574178Z",
  "published": "2026-07-25T10:17:13.640Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64322"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64322"
  ]
}