cbcvebase.
CVE-2026-53369
published 2026-07-19

CVE-2026-53369: In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification…

PriorityP341high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.14%
3.7th percentile
In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. Reject such descriptors instead of silently accepting them. A legitimate single-block descriptor should never have a CRC length that exceeds the block.

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 832ab4a882dc9b3c0155490d9993642ef545fd22832ab4a882dc9b3c0155490d9993642ef545fd22
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7d1b6adbf90df6c8941090d5646fbeca25ba97707d1b6adbf90df6c8941090d5646fbeca25ba9770
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3dede76d525919bb966f9213e131af685de5ff993dede76d525919bb966f9213e131af685de5ff99
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 50dfaf4a027742b4fcdc3e9305e7199ece9bc6a650dfaf4a027742b4fcdc3e9305e7199ece9bc6a6
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 31605bbe94557bff721eaf041001169d44ac6f9831605bbe94557bff721eaf041001169d44ac6f98
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1873eb81c65d3f849418d7386baa39c439c9fc381873eb81c65d3f849418d7386baa39c439c9fc38
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fdb26e628d2a211a23815d375bd33bdf863344e2fdb26e628d2a211a23815d375bd33bdf863344e2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 55d41b0a20128e86b9e960dd2e3f0a2d69a18df755d41b0a20128e86b9e960dd2e3f0a2d69a18df7
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.12.1 < 5.10.2585.10.258
linuxlinux_kernel>= 5.11 < 5.15.2095.15.209
linuxlinux_kernel>= 5.16 < 6.1.1756.1.175
linuxlinux_kernel>= 6.13 < 6.18.306.18.30
linuxlinux_kernel>= 6.19 < 7.0.77.0.7
linuxlinux_kernel>= 6.2 < 6.6.1406.6.140
linuxlinux_kernel>= 6.7 < 6.12.886.12.88
ubuntulinux
ubuntulinux-aws

CVSS provenance

nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.4HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.