CVE-2026-45991

Aliases:UBUNTU-CVE-2026-45991DEBIAN-CVE-2026-45991CGA-3cpp-vq7x-34m3CGA-3q2r-m46g-gcx5CGA-4433-q5hf-j39pCGA-gcf3-3734-x3p7CGA-gmpq-mr9r-7m2vCGA-gvg6-fh38-h6wcCGA-q76v-33qm-7p64CGA-rq5f-qjjv-p63mCGA-vm79-pcx5-2jfwCGA-wgq2-hmx5-9833CGA-xxcw-j744-j838CGA-cr28-x6rv-qqfgCGA-j94q-m7c3-9g4pCGA-24p7-xp35-993qCGA-27f6-3jf7-58x9CGA-27fp-xmh3-wc4xCGA-2h37-q528-2xvvCGA-2mqf-972g-ph38CGA-3pxp-pxv6-v958CGA-3qqf-qx7g-2jjwCGA-3w63-xcgc-j8ppCGA-426v-hprr-g9fgCGA-48q7-2j4f-ggvvCGA-4p26-88gv-746mCGA-4wc7-3986-fv65CGA-5c23-5mfg-85c7CGA-5xmm-f95f-9rxpCGA-6xqr-9wm4-7ghjCGA-7mr7-p7j8-42qxCGA-8chr-x579-fp42CGA-8q48-mgrq-j9rfCGA-925f-756f-px3wCGA-9j5f-9v36-w349CGA-9m92-96x7-hqmfCGA-9p4m-qq2f-pwrvCGA-cgvw-pvmh-5h5fCGA-cv4f-xgrf-rjc4CGA-f2m4-5vfq-57v5CGA-f34x-53jp-4fjpCGA-f72p-f7r3-rf74CGA-fg37-2r56-hp9pCGA-fgjc-mm6p-mvmvCGA-fvqg-24w7-5p6vCGA-gg9q-67cm-947xCGA-ggg9-cfxm-5x8mCGA-gj49-qf2m-jp6gCGA-gmf3-6vmp-3fp5CGA-gqr7-x764-79vmCGA-h2gf-h6g5-5gcvCGA-h4hr-q339-26phCGA-hfcj-gr68-qx3rCGA-j6q6-x888-8787CGA-jpmr-98qp-q2rgCGA-m9qg-jwhx-95cxCGA-mmcm-jmpq-qj98CGA-mmhr-gmr4-xhjcCGA-mqpg-h6fh-c7x2CGA-mw5g-3vq7-xrx4CGA-p376-pcc8-w2wwCGA-p4v9-xf3c-vvwqCGA-p59p-g79f-pc6jCGA-pc89-35mv-gf49CGA-pgqc-7mv9-r27wCGA-phvw-w6v2-fxhcCGA-ppfr-2cf6-58qrCGA-q9hj-xqgm-mqp3CGA-qg64-jjc6-ppv9CGA-qp9w-w4m9-3489CGA-r2qc-8g28-w7c8CGA-r3v3-9734-6ch8CGA-r6q6-8rw7-624rCGA-rgf2-jxc8-ccr5CGA-rmpq-6wvj-qvp7CGA-rw74-jxxh-xc6fCGA-v393-8vm7-jr5pCGA-v5rr-f6w9-36f6CGA-v77j-8h52-3rx3CGA-vvpv-8m64-72mfCGA-w369-rf8v-vrfpCGA-w4q6-8674-8hx3CGA-wcjr-38hp-8g8jCGA-wrqr-2gmv-3m9mCGA-x3xg-gc9w-2957CGA-xg52-xp9h-6x83CGA-xmw7-pw4v-2x3xCGA-xwgj-h95c-ggrgCGA-cjf6-qgc7-w6mqCGA-fj42-gq9v-5863CGA-r92v-3wgg-xr4r
Modified
Published: 27 May 2026, 12:55
Last modified:05 Aug 2026, 12:29

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
0.17% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 May 2026, 12:55
Published
Vulnerability first disclosed
05 Aug 2026, 12:29
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: udf: fix partition descriptor append bookkeeping Mounting a crafted UDF image with repeated partition descriptors can trigger a heap out-of-bounds write in part_descs_loc[]. handle_partition_descriptor() deduplicates entries by partition number, but appended slots never record partnum. As a result duplicate Partition Descriptors are appended repeatedly and num_part_descs keeps growing. Once the table is full, the growth path still sizes the allocation from partnum even though inserts are indexed by num_part_descs. If partnum is already aligned to PART_DESC_ALLOC_STEP, ALIGN(partnum, step) can keep the old capacity and the next append writes past the end of the table. Store partnum in the appended slot and size growth from the next append count so deduplication and capacity tracking follow the same model.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.17% Percentile: 7%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • chainguardhyperv-daemons-6.18

    all

  • chainguardlinux-aws-6.18

    all

  • chainguardlinux-aws-6.18-boot-installed

    all

  • chainguardlinux-aws-6.18-bootc

    all

  • chainguardlinux-aws-6.18-bootc-boot-installed

    all

  • chainguardlinux-aws-6.18-fips-boot-installed

    all

  • chainguardlinux-aws-6.18-headers

    all

  • chainguardlinux-aws-6.18-modules

    all

  • chainguardlinux-azure-6.18

    all

  • chainguardlinux-azure-6.18-boot-installed

    all

  • chainguardlinux-azure-6.18-fips-boot-installed

    all

  • chainguardlinux-azure-6.18-headers

    all

  • chainguardlinux-azure-6.18-modules

    all

  • chainguardlinux-desktop-6.18

    all

  • chainguardlinux-desktop-6.18-bootc

    all

  • chainguardlinux-desktop-6.18-bootc-boot-installed

    all

  • chainguardlinux-desktop-6.18-headers

    all

  • chainguardlinux-desktop-6.18-modules

    all

  • chainguardlinux-firecracker-6.18

    all

  • chainguardlinux-gcp-6.18

    all

  • chainguardlinux-gcp-6.18-boot-installed

    all

  • chainguardlinux-gcp-6.18-bootc

    all

  • chainguardlinux-gcp-6.18-bootc-boot-installed

    < 6.18.38-r2 | all

  • chainguardlinux-gcp-6.18-fips-boot-installed

    all

  • chainguardlinux-gcp-6.18-headers

    all

  • chainguardlinux-gcp-6.18-modules

    all

  • chainguardlinux-qemu-6.18

    all

  • chainguardlinux-qemu-6.18-boot-installed

    all

  • chainguardlinux-qemu-6.18-bootc

    all

  • chainguardlinux-qemu-6.18-bootc-boot-installed

    < 6.18.38-r2 | all

  • chainguardlinux-qemu-6.18-fips-boot-installed

    all

  • chainguardlinux-qemu-6.18-headers

    all

  • chainguardlinux-qemu-6.18-modules

    all

  • chainguardlinux-qemu-melange

    all | < 6.18.49-r2

  • chainguardlinux-vmware-6.18

    all

  • chainguardlinux-vmware-6.18-boot-installed

    all

  • chainguardlinux-vmware-6.18-fips-boot-installed

    all

  • chainguardlinux-vmware-6.18-headers

    all

  • chainguardlinux-vmware-6.18-modules

    all

  • debianlinux

    < 5.10.259-1 | < 6.1.176-1 | < 6.12.88-1 | < 7.0.4-1

  • debianlinux-6.1

    < 6.1.176-1~deb11u1

  • ubuntulinux

    all | all | < 6.8.0-136.136 | all | < 7.0.0-27.27

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | all | < 6.8.0-1061.64 | all | < 7.0.0-1008.8

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    all

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

Showing first 50 affected entries in server-rendered view.

References (34)