CVE-2026-63808
Received Received - Intake

Use-After-Free in Linux Kernel exFAT Filesystem

Vulnerability report for CVE-2026-63808, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-19

Last updated on: 2026-07-19

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the fall-through TYPE_EXTEND branch reads the directory entry through ep (which points into bh->b_data): brelse(bh); if (entry_type == TYPE_EXTEND) { ... len = exfat_extract_uni_name(ep, entry_uniname); ... } After brelse() drops our reference, nothing guarantees that the underlying page backing bh->b_data remains valid for the subsequent exfat_extract_uni_name() read. This is the same pattern fixed in commit fc961522ddbd ("exfat: Fix potential use after free in exfat_load_upcase_table()"). Move brelse(bh) so it runs after ep is no longer dereferenced on each branch. Confirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y + CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image (long filename with same-hash collisions forcing the TYPE_EXTEND path). With a debug-only invalidate_bdev() inserted between brelse(bh) and the ep read to make the stale-deref window deterministic, the unpatched kernel faults: BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0 BUG: unable to handle page fault for address: ffff88801a5fa0c2 Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0 With this patch applied, the same instrumented harness completes cleanly under the same sanitizer stack. I have not reproduced a crash on an uninstrumented kernel under ordinary reclaim; the instrumented A/B establishes the lifetime violation and that the patch closes it, not an unaided triggerability claim.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-19
Last Modified
2026-07-19
Generated
2026-07-20
AI Q&A
2026-07-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's exFAT file system driver. It occurs in the exfat_find_dir_entry() function where a buffer holding directory entry data is freed too early. Specifically, the code releases the buffer with brelse(bh) before finishing all reads from that buffer. If the code path reaches the TYPE_EXTEND branch, it tries to read the directory entry through a pointer into the now-freed buffer, causing a potential use-after-free condition.

Detection Guidance

This vulnerability is specific to the Linux kernel's exFAT filesystem handling and requires kernel-level detection. It cannot be detected via network scans or standard commands. The issue is triggered by crafted exFAT images with specific filename conditions. Monitor kernel logs for use-after-free errors or crashes in exfat_find_dir_entry() after mounting exFAT filesystems.

Impact Analysis

This vulnerability could allow an attacker with access to craft a malicious exFAT filesystem to trigger a use-after-free condition. This might lead to kernel memory corruption, crashes, or potentially privilege escalation if exploited. Systems using vulnerable Linux kernels with exFAT support could be affected by filesystem operations on untrusted exFAT media.

Compliance Impact

This vulnerability is a use-after-free flaw in the Linux kernel's exFAT file system handling. It does not directly relate to data privacy or security controls required by standards like GDPR or HIPAA. Compliance impact would depend on whether this flaw could lead to unauthorized data access or corruption in systems processing sensitive data.

Mitigation Strategies

Apply the kernel patch that moves brelse(bh) after all dereferences of ep. Avoid mounting untrusted exFAT filesystems until patched. If using a vulnerable kernel, restrict exFAT usage to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63808. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart