【活用ガイド】

JVNDB-2026-031802

LinuxのLinux Kernelにおける境界外読み取りに関する脆弱性

概要

Linuxカーネルにおいて、以下の脆弱性が修正されました:tracingのglobマッチングにおける境界外読み取りの防止。文字列イベントフィールドは必ずしもNUL終端されているわけではないため、フィルタ述語関数(filter_pred_string()、filter_pred_strloc()、filter_pred_strrelloc())はフィールドの長さを正規表現マッチのコールバックに渡し、その長さに対応したマッチャーがそれを尊重します。例外はregex_match_glob()であり、これは長さを無視してglob_match()を呼び出し、文字列をNULバイトに達するまで走査していました。しかし、一部の文字列フィールドはNUL終端されていません。例えば、xfs_*名前空間のトレースポイントの動的なchar配列がこれに該当し、末尾にNULがないままコピーされています。そのようなフィールドの場合、globマッチングはイベントフィールドの終端を越えて読み取りを行い、xfs_lookupトレースポイント経由でregex_match_glob()とfilter_match_preds()を通じてglob_match()内でKASANのスラブ境界外読み取りが発生していました。長さ制限付きのglob_match_len()を追加し、regex_match_glob()からこれを使用することで、globマッチングが常にフィールドの境界で停止するようにしました。マッチングループは共通のヘルパー関数に切り出されており、glob_match()の挙動は従来通り保持されています。
CVSS による深刻度 (CVSS とは?)

CVSS v3 による深刻度
基本値: 7.1 (重要) [その他]
  • 攻撃元区分: ローカル
  • 攻撃条件の複雑さ: 低
  • 攻撃に必要な特権レベル: 低
  • 利用者の関与: 不要
  • 影響の想定範囲: 変更なし
  • 機密性への影響(C): 高
  • 完全性への影響(I): なし
  • 可用性への影響(A): 高
影響を受けるシステム


Linux
  • Linux Kernel 4.10 以上 5.10.261 未満
  • Linux Kernel 5.11 以上 5.15.212 未満
  • Linux Kernel 5.16 以上 6.1.178 未満
  • Linux Kernel 6.13 以上 6.18.39 未満
  • Linux Kernel 6.19 以上 7.1.4 未満
  • Linux Kernel 6.2 以上 6.6.145 未満
  • Linux Kernel 6.7 以上 6.12.96 未満
  • Linux Kernel 7.2

想定される影響

・当該ソフトウェアが扱う全ての情報が外部に漏れる可能性があります。
・当該ソフトウェアが扱う情報について、書き換えは発生しません。
・当該ソフトウェアが完全に停止する可能性があります。
対策

リリース情報、またはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。
ベンダ情報

CWEによる脆弱性タイプ一覧  CWEとは?

  1. 境界外読み取り(CWE-125) [NVD評価]
共通脆弱性識別子(CVE)  CVEとは?

  1. CVE-2026-64299
参考情報

  1. National Vulnerability Database (NVD) : CVE-2026-64299
  2. 関連文書 : tracing: Prevent out-of-bounds read in glob matching - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/ee5b8888d3248618251fb69a2fad92afcb81557e)
  3. 関連文書 : tracing: Prevent out-of-bounds read in glob matching - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/265f3a690f6c7d69ef7d2ca50b04b4853a211df3)
  4. 関連文書 : tracing: Prevent out-of-bounds read in glob matching - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/56d4c9ab84714eebb285a2fee68aaedf81e3ef15)
  5. 関連文書 : tracing: Prevent out-of-bounds read in glob matching - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/2dad64a97e1df47f5d9ccb17fa319aa348617226)
  6. 関連文書 : tracing: Prevent out-of-bounds read in glob matching - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/35ae19764eabfe9c29029d3b5713c86e6855acdf)
  7. 関連文書 : tracing: Prevent out-of-bounds read in glob matching - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/0a6070839b1ef276d5b05bedfb787743e140fb17)
  8. 関連文書 : tracing: Prevent out-of-bounds read in glob matching - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/e5d5f3bd053a5f14787526c9f0f55ef900d43ac6)
  9. 関連文書 : tracing: Prevent out-of-bounds read in glob matching - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/ebb55902856973906c8bb339a3a34824ed4a5086)
更新履歴

  • [2026年09月04日]
      掲載