Junglewise Threat Intelligence

CVE-2026-43067: Linux Kernel ext4 out-of-bounds block allocation in mballoc

CVE-2026-43067 · Severity: critical · CVSS 9.8 · Published 2026-05-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's ext4 file system, which is widely used for data storage. The flaw occurs when the system attempts to allocate storage space for certain types of files, potentially allowing data to be written to unintended locations. This could lead to system instability, data corruption, or unauthorized access to sensitive information.

Technical details

A vulnerability in the ext4 multi-block allocator (mballoc.c) arises from improper bounds checking when searching for blocks for indirect-mapped files. Specifically, if the goal group (ac_g_ex.fe_group) is greater than or equal to the total number of groups (ngroups), the initial iteration of ext4_mb_scan_groups_linear() can proceed with an unsupported group index before next_linear_group() is called. This occurs in environments where a mix of extent-mapped and indirect-block mapped files exist. An attacker could potentially leverage this to cause out-of-bounds writes or memory corruption. The fix introduces a safety clamp in ext4_mb_scan_groups() to reset the start group to zero if it exceeds the valid range.

Affected products

  • Linux Linux Kernel 5.15.203 to 5.16, 6.1.167, 6.6.130 to 6.6.134, 6.12.77 to 6.12.80, 6.18.14 to 6.18.21, 6.19.4 to 6.19.11

Timeline

  • 2026-03-26: patched: Initial patch authored by Theodore Ts'o
  • 2026-05-05: disclosed: CVE published

References