Executive brief
The Linux kernel's ocfs2 filesystem implementation contains a buffer overflow vulnerability in its refcount tree management code. When unlinking a file with reference counting, the kernel may write beyond allocated memory boundaries, potentially causing a system crash or kernel panic. This affects systems using ocfs2-formatted storage volumes.
Technical details
The vulnerability is a heap buffer overflow in the ocfs2 (Oracle Cluster Filesystem 2) module's refcount tree handling, specifically in the ocfs2_remove_refcount_extent() function. When removing the last leaf block from a refcount tree, the code performed an unbounded memset on the rf_records structure. Due to an aliased union member (rf_list.l_tree_depth overlapping rf_records.rl_count), the memset would write past the declared 16-byte boundary of rf_records. The kernel's fortify checker detected this out-of-bounds write. The fix restricts the memset to only the rl_recs array after properly setting rl_count. Attack requires local filesystem access to trigger the code path by unlinking a refcounted file on an ocfs2 volume. A patch is available in the stable kernel tree (commit 1ec3cca2d8b6b9ff6584ca626d4c8918bbf48d44).
Affected products
- Linux Linux kernel Multiple versions through at least 6.18
Timeline
- 2026-08-28: disclosed
- 2026-06-04: patched