HIGH Introduced in 6.15
fs/statmount IdMap OOB Write
CVE-2026-64074
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap statmount_mnt_idmap() writes one mapping with seq_printf() and then manually advances seq->count to include the NUL separator. If seq_printf() overflows, seq_set_overflow() sets seq->count to seq->size. The manual seq->count++ changes this to seq->size + 1. seq_has_overflowed() then no longer detects the overflow. The corrupted count returns to statmount_string(), which later executes: seq->buf[seq->count++] = '\0'; This causes a 1-byte NULL out-of-bounds write on the dynamically allocated seq buffer. Fix this by checking for overflow immediately after seq_printf().
02KernelScan AI Analysis
Risk summary
A local unprivileged user can trigger a 1-byte NULL out-of-bounds write on a dynamically allocated kernel heap buffer by calling statmount() with STATMOUNT_MNT_UIDMAP or STATMOUNT_MNT_GIDMAP on an idmapped mount. This heap corruption can potentially be exploited for privilege escalation. The vulnerability was introduced in Linux 6.15 and affects kernels up to 6.18.34 and 7.0.11.
Vulnerability analysis
The root cause is in statmount_mnt_idmap() in fs/mnt_idmapping.c. After calling seq_printf() to write a UID/GID mapping entry, the code unconditionally increments seq->count to account for a NUL separator. If seq_printf() overflowed the buffer, seq_set_overflow() sets seq->count to seq->size (the sentinel overflow value). The subsequent seq->count++ advances it to seq->size + 1, which is beyond the sentinel, causing seq_has_overflowed() to return false. The corrupted count propagates back to statmount_string(), which then executes seq->buf[seq->count++] = '\0', writing a NUL byte one position past the end of the allocated seq buffer — a 1-byte heap out-of-bounds write. The fix adds an overflow check immediately after seq_printf() and returns -EAGAIN before the manual increment, so the overflow is properly detected and handled. The attack surface is the statmount(2) syscall, which is accessible to unprivileged local users querying idmapped mounts. No special privileges beyond a local account are required to trigger the overflow, though reliable exploitation requires heap layout manipulation (AC:High).
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 6.15 | 7.1 | a3bf0f28d4ba |
| 7.0 | 6.15 | 7.0.11 | 93614949dc86 |
| 6.18 | 6.15 | 6.18.34 | e37ea2c6f17f |