Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-63808

42
FAUCET Score

In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the fall-through TYPE_EXTEND branch reads the directory entry through ep (which points into bh->b_data): brelse(bh); if (entry_type == TYPE_EXTEND) { ... len = exfat_extract_uni_name(ep, entry_uniname); ... } After brelse() drops our reference, nothing guarantees that the underlying page backing bh->b_data remains valid for the subsequent exfat_extract_uni_name() read. This is the same pattern fixed in commit fc961522ddbd ("exfat: Fix potential use after free in exfat_load_upcase_table()"). Move brelse(bh) so it runs after ep is no longer dereferenced on each branch. Confirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y + CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image (long filename with same-hash collisions forcing the TYPE_EXTEND path). With a debug-only invalidate_bdev() inserted between brelse(bh) and the ep read to make the stale-deref window deterministic, the unpatched kernel faults: BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0 BUG: unable to handle page fault for address: ffff88801a5fa0c2 Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0 With this patch applied, the same instrumented harness completes cleanly under the same sanitizer stack. I have not reproduced a crash on an uninstrumented kernel under ordinary reclaim; the instrumented A/B establishes the lifetime violation and that the patch closes it, not an unaided triggerability claim.

First published: Jul 19, 2026Last modified: Jul 20, 2026

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
5.7CNA affecteddefault affected
LinuxLinux
>= ca06197382bde0a3bc20215595d1c9ce20c6e341, < 06c4e1e9967d332ac33ba38b7819851089ff9359, >= ca06197382bde0a3bc20215595d1c9ce20c6e341, < 3f5f8ee9917cc2b9076ac533492d8a200edcabb8, >= ca06197382bde0a3bc20215595d1c9ce20c6e341, < 4d101016d5e587f820b3ae2d5bb6770d86342649, >= ca06197382bde0a3bc20215595d1c9ce20c6e341, < 708b97e792945d3e4653939fd3405d71a61ad065, >= ca06197382bde0a3bc20215595d1c9ce20c6e341, < 8e0abc17fbd7e305802e84fe98b4950d50f9c433, >= ca06197382bde0a3bc20215595d1c9ce20c6e341, < adfacfbaeae2cb760f492357cc36b41f84ef7f86, >= ca06197382bde0a3bc20215595d1c9ce20c6e341, < e48f413c2815787b8cade2795e194e3c4cd782ef, >= ca06197382bde0a3bc20215595d1c9ce20c6e341, < e6f1a11cfb808441a43ffae9b476cc135732cd27CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.50%
Probability of exploitation in next 30 days
EPSS Percentile
39.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0050 is in the 18th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Jul/CVE-2026-63808Important

exfat: fix potential use-after-free in exfat_find_dir_entry()

Jul 14, 2026

References

git.kernel.org / stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359
git.kernel.org / stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8
git.kernel.org / stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649
git.kernel.org / stable/c/708b97e792945d3e4653939fd3405d71a61ad065
git.kernel.org / stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433
git.kernel.org / stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86
git.kernel.org / stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef
git.kernel.org / stable/c/e6f1a11cfb808441a43ffae9b476cc135732cd27