Junglewise Threat Intelligence

CVE-2026-80638: Linux kernel ocfs2 out-of-bounds write in refcount tree

CVE-2026-80638 · Severity: high · CVSS 8.8 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ocfs2 filesystem implementation contains a buffer overflow vulnerability in its refcount tree management code. When unlinking a file with reference counting, the kernel may write beyond allocated memory boundaries, potentially causing a system crash or kernel panic. This affects systems using ocfs2-formatted storage volumes.

Technical details

The vulnerability is a heap buffer overflow in the ocfs2 (Oracle Cluster Filesystem 2) module's refcount tree handling, specifically in the ocfs2_remove_refcount_extent() function. When removing the last leaf block from a refcount tree, the code performed an unbounded memset on the rf_records structure. Due to an aliased union member (rf_list.l_tree_depth overlapping rf_records.rl_count), the memset would write past the declared 16-byte boundary of rf_records. The kernel's fortify checker detected this out-of-bounds write. The fix restricts the memset to only the rl_recs array after properly setting rl_count. Attack requires local filesystem access to trigger the code path by unlinking a refcounted file on an ocfs2 volume. A patch is available in the stable kernel tree (commit 1ec3cca2d8b6b9ff6584ca626d4c8918bbf48d44).

Affected products

  • Linux Linux kernel Multiple versions through at least 6.18

Timeline

  • 2026-08-28: disclosed
  • 2026-06-04: patched

References

Related threats