Junglewise Threat Intelligence

CVE-2026-63796: Linux Kernel OCFS2 use-after-free in group bitmap descriptors

CVE-2026-63796 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's OCFS2 file system component, which is used for managing shared storage in cluster environments. A malicious or corrupted file system descriptor could cause the system to crash or behave unpredictably by claiming more memory than is physically available for certain internal operations. This could lead to a denial of service, impacting the availability of the server and any hosted applications.

Technical details

A vulnerability in the OCFS2 file system driver's ocfs2_validate_gd_parent() function allows for a use-after-free condition. The root cause is an insufficient validation of the bg_bits and bg_size parameters within group descriptors; while they were checked against chain geometry, they were not capped by the physical size of the descriptor block. A specially crafted or malicious descriptor can claim a size that exceeds the physical bitmap capacity, causing subsequent bitmap scans and bit updates to access memory outside the intended buffer. This was confirmed via KASAN reports showing a use-after-free in _find_next_bit. Patches have been released to add a physical-cap check using ocfs2_group_bitmap_size().

Affected products

  • Linux Linux Kernel ocfs2 module

Timeline

  • 2026-05-24: disclosed: Initial patch submission by Zhang Cen
  • 2026-07-04: patched: Commits merged into stable trees by Greg Kroah-Hartman
  • 2026-07-19: advisory: CVE-2026-63796 published in NVD

References

Related threats