0.0
NA
CVE-2026-63808
exfat: fix potential use-after-free in exfat_find_dir_entry()
Description

In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the fall-through TYPE_EXTEND branch reads the directory entry through ep (which points into bh->b_data): brelse(bh); if (entry_type == TYPE_EXTEND) { ... len = exfat_extract_uni_name(ep, entry_uniname); ... } After brelse() drops our reference, nothing guarantees that the underlying page backing bh->b_data remains valid for the subsequent exfat_extract_uni_name() read. This is the same pattern fixed in commit fc961522ddbd ("exfat: Fix potential use after free in exfat_load_upcase_table()"). Move brelse(bh) so it runs after ep is no longer dereferenced on each branch. Confirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y + CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image (long filename with same-hash collisions forcing the TYPE_EXTEND path). With a debug-only invalidate_bdev() inserted between brelse(bh) and the ep read to make the stale-deref window deterministic, the unpatched kernel faults: BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0 BUG: unable to handle page fault for address: ffff88801a5fa0c2 Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0 With this patch applied, the same instrumented harness completes cleanly under the same sanitizer stack. I have not reproduced a crash on an uninstrumented kernel under ordinary reclaim; the instrumented A/B establishes the lifetime violation and that the patch closes it, not an unaided triggerability claim.

INFO

Published Date :

July 19, 2026, 12:16 p.m.

Last Modified :

July 19, 2026, 12:16 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-63808 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Fix a use-after-free vulnerability in exfat by adjusting buffer_head release timing.
  • Update the Linux kernel to include the fix.
  • Ensure buffer_head is released after use.
  • Review related memory management functions.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-63808 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-63808 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-63808 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-63808 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 19, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ca06197382bde0a3bc20215595d1c9ce20c6e341', 'lessThan': 'e6f1a11cfb808441a43ffae9b476cc135732cd27', 'versionType': 'git'}, {'status': 'affected', 'version': 'ca06197382bde0a3bc20215595d1c9ce20c6e341', 'lessThan': 'e48f413c2815787b8cade2795e194e3c4cd782ef', 'versionType': 'git'}, {'status': 'affected', 'version': 'ca06197382bde0a3bc20215595d1c9ce20c6e341', 'lessThan': '06c4e1e9967d332ac33ba38b7819851089ff9359', 'versionType': 'git'}, {'status': 'affected', 'version': 'ca06197382bde0a3bc20215595d1c9ce20c6e341', 'lessThan': '8e0abc17fbd7e305802e84fe98b4950d50f9c433', 'versionType': 'git'}, {'status': 'affected', 'version': 'ca06197382bde0a3bc20215595d1c9ce20c6e341', 'lessThan': '4d101016d5e587f820b3ae2d5bb6770d86342649', 'versionType': 'git'}, {'status': 'affected', 'version': 'ca06197382bde0a3bc20215595d1c9ce20c6e341', 'lessThan': 'adfacfbaeae2cb760f492357cc36b41f84ef7f86', 'versionType': 'git'}, {'status': 'affected', 'version': 'ca06197382bde0a3bc20215595d1c9ce20c6e341', 'lessThan': '708b97e792945d3e4653939fd3405d71a61ad065', 'versionType': 'git'}, {'status': 'affected', 'version': 'ca06197382bde0a3bc20215595d1c9ce20c6e341', 'lessThan': '3f5f8ee9917cc2b9076ac533492d8a200edcabb8', 'versionType': 'git'}], 'programFiles': ['fs/exfat/dir.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.260', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.211', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.177', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.144', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.95', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.38', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.3', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/exfat/dir.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the fall-through TYPE_EXTEND branch reads the directory entry through ep (which points into bh->b_data): brelse(bh); if (entry_type == TYPE_EXTEND) { ... len = exfat_extract_uni_name(ep, entry_uniname); ... } After brelse() drops our reference, nothing guarantees that the underlying page backing bh->b_data remains valid for the subsequent exfat_extract_uni_name() read. This is the same pattern fixed in commit fc961522ddbd ("exfat: Fix potential use after free in exfat_load_upcase_table()"). Move brelse(bh) so it runs after ep is no longer dereferenced on each branch. Confirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y + CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image (long filename with same-hash collisions forcing the TYPE_EXTEND path). With a debug-only invalidate_bdev() inserted between brelse(bh) and the ep read to make the stale-deref window deterministic, the unpatched kernel faults: BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0 BUG: unable to handle page fault for address: ffff88801a5fa0c2 Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0 With this patch applied, the same instrumented harness completes cleanly under the same sanitizer stack. I have not reproduced a crash on an uninstrumented kernel under ordinary reclaim; the instrumented A/B establishes the lifetime violation and that the patch closes it, not an unaided triggerability claim.
    Added Reference https://git.kernel.org/stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359
    Added Reference https://git.kernel.org/stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8
    Added Reference https://git.kernel.org/stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649
    Added Reference https://git.kernel.org/stable/c/708b97e792945d3e4653939fd3405d71a61ad065
    Added Reference https://git.kernel.org/stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433
    Added Reference https://git.kernel.org/stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86
    Added Reference https://git.kernel.org/stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef
    Added Reference https://git.kernel.org/stable/c/e6f1a11cfb808441a43ffae9b476cc135732cd27
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.