CVE-2026-93055
In the Linux kernel, the following vulnerability has been resolved: UDF symlink pathComponent header OOB read udf_symlink_filler() can enter udf_pc_to_char() with a partial pathComponent header. Validate that enough input remains for a complete pathComponent header before accessing it. Reject malformed symlink data that would otherwise make udf_pc_to_char() perform an out-of-bounds read.
- Published Sep 17, 2026
- Not yet scored
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available