Junglewise Threat Intelligence

CVE-2026-74350: Linux kernel ocfs2 symlink validation buffer over-read

CVE-2026-74350 · Severity: critical · CVSS 9.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's OCFS2 filesystem contains a validation gap that allows specially crafted symlink inodes to trigger a buffer over-read. An attacker with the ability to create or modify OCFS2 filesystem images could exploit this to cause a kernel crash (denial of service) or potentially leak sensitive kernel memory. This affects systems using OCFS2, commonly deployed in clustered storage environments.

Technical details

The vulnerability exists in OCFS2's fast symlink handling, specifically in ocfs2_fast_symlink_read_folio(). When a "zero-cluster" symlink inode is loaded, the kernel uses strnlen() on the inline payload and copies len + 1 bytes into a folio. If a malicious or corrupt dinode stores an i_size that does not fit within the inline area or lacks a NUL terminator at i_size, the memcpy operation reads past the inode block buffer boundary. The root cause is insufficient validation in ocfs2_validate_inode_block(), which failed to reject fast symlinks with oversized or unterminated inline payloads. The fix adds validation to reject zero-cluster symlink dinodes whose i_size exceeds inline capacity or whose payload lacks proper NUL termination. Attack precondition requires filesystem access to craft a malicious OCFS2 image; no network vector or privilege escalation is required for the core buffer over-read.

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: patched

Related threats