Kernel-level vuln in the widely deployed Linux exFAT driver (CVSS 9.8) can crash or compromise systems mounting exFAT media; impacts broad infrastructure and requires org-wide action.
CVE-2026-63808
Use-after-free in Linux exFAT driver allows kernel crash or potential kernel-level compromise via crafted media.
Is CVE-2026-63808 being exploited?
Not confirmed. CVE-2026-63808 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.53% probability of exploitation in the next 30 days.
How severe is CVE-2026-63808?
CVE-2026-63808 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63808?
Yes. A fix has been recorded for CVE-2026-63808. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63808 affect?
CVE-2026-63808 affects Linux kernel (exFAT driver), Major Linux distributions with exfat module, Systems mounting exFAT volumes (USB/SD/VM images). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63808?
Apply vendor kernel updates immediately; unmount/block exFAT mounts and disable auto-mount until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Malformed exFAT images or mounted media can trigger a kernel use-after-free, causing crashes and possible privilege escalation or RCE.
Immediate action required
- affected>= ca06197382bde0a3bc20215595d1c9ce20c6e341 and < e6f1a11cfb808441a43ffae9b476cc135732cd27
- affected>= ca06197382bde0a3bc20215595d1c9ce20c6e341 and < e48f413c2815787b8cade2795e194e3c4cd782ef
- affected>= ca06197382bde0a3bc20215595d1c9ce20c6e341 and < 06c4e1e9967d332ac33ba38b7819851089ff9359
- affected>= ca06197382bde0a3bc20215595d1c9ce20c6e341 and < 8e0abc17fbd7e305802e84fe98b4950d50f9c433
- affected>= ca06197382bde0a3bc20215595d1c9ce20c6e341 and < 4d101016d5e587f820b3ae2d5bb6770d86342649
- affected>= ca06197382bde0a3bc20215595d1c9ce20c6e341 and < adfacfbaeae2cb760f492357cc36b41f84ef7f86
- affected>= ca06197382bde0a3bc20215595d1c9ce20c6e341 and < 708b97e792945d3e4653939fd3405d71a61ad065
- affected>= ca06197382bde0a3bc20215595d1c9ce20c6e341 and < 3f5f8ee9917cc2b9076ac533492d8a200edcabb8
- affected5.7
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.