Executive brief
A vulnerability in the Linux kernel's ext2 filesystem driver could allow a system crash or denial of service. By using a specially crafted disk image or corrupted filesystem, an attacker can trigger internal kernel errors during file operations like renaming or deleting. This issue primarily affects systems that mount untrusted external storage media or disk images using the older ext2 format.
Technical details
A vulnerability exists in the ext2_iget() function of the Linux kernel's ext2 driver where it fails to reject inodes with a link count (i_nlink) of zero that also possess a valid mode and no deletion time (i_dtime). In a healthy ext2 filesystem, such a state is impossible and indicates corruption. An attacker can exploit this by providing a crafted filesystem image; when the Virtual File System (VFS) attempts to perform operations like unlink, rename, or rmdir on such an inode, it triggers a WARN_ON in drop_nlink() within fs/inode.c. The fix involves extending the validation logic in ext2_iget() to catch this specific corruption state and return -EFSCORRUPTED, preventing the invalid inode from reaching the VFS layer.
Affected products
- Linux Linux kernel Fixed in 6.12.77+ and other stable branches
Timeline
- 2026-04-04: other: Patch authored by Vasiliy Kovalev
- 2026-05-27: disclosed: CVE published via kernel.org and NVD
References
- https://git.kernel.org/stable/c/25947cc5b2374cd5bf627fe3141496444260d04f
- https://git.kernel.org/stable/c/2dde6377ab2e46bb80cf066c659ef016f3ad7a9b
- https://git.kernel.org/stable/c/32e0b925572686399243834ec99e2a9d85c62eae
- https://git.kernel.org/stable/c/470264bbec499e276a89a6431144ae58f411ea4d
- https://git.kernel.org/stable/c/d3af04a43db86379df7438bf8bade71685b8a239