Executive brief
OCFS2 is a clustered file system used in enterprise storage environments. A malformed on-disk data structure can trigger a kernel panic when writing to an affected file, causing service disruption and potential data loss. This requires an attacker to corrupt the file system on disk or mount a malicious OCFS2 image.
Technical details
The vulnerability is an array index out-of-bounds condition in the OCFS2 file system driver. The function ocfs2_sum_rightmost_rec() computes an array index by subtracting 1 from an unvalidated l_next_free_rec field; when this field is 0, the index becomes -1, and when it exceeds l_count, the index falls past the array bounds. This violates __counted_by_le(l_count) annotations and triggers UBSAN (undefined behavior sanitizer) panics. The fix validates the embedded extent list at inode read time in ocfs2_validate_inode_block(), ensuring l_count is non-zero and within limits, and that l_next_free_rec does not exceed l_count. Attack vector is local: an attacker must provide a corrupted OCFS2 image or modify on-disk metadata. A patch is available in the Linux kernel stable tree.
Affected products
- Linux Linux kernel multiple versions (patch backported across 2.6.11 through 7.1+)
Timeline
- 2026-08-15: disclosed: Published on NVD
- 2026-06-17: patched: Patch committed upstream as 452a8467be8143747292218212671deeb186d2ae
- 2026-07-24: patched: Backported to stable kernels