Executive brief
The OCFS2 filesystem driver in the Linux kernel has a memory leak bug triggered during copy-on-write operations on the same filesystem. When using copy_file_range() on files within OCFS2, memory allocated for deallocation tracking is not freed, causing gradual memory exhaustion and potential denial of service if the operation is repeated.
Technical details
The vulnerability is a memory leak in the OCFS2 (Oracle Cluster Filesystem 2) subsystem, specifically in the deallocation handling code during copy-on-write completion. When copy_file_range() is used on files within the same OCFS2 filesystem, the ocfs2_cache_block_dealloc() function allocates memory structures (32-byte objects tracked in deallocation lists) but these are not properly freed after the cow (copy-on-write) operation completes, as seen through kmemleak detection. The vulnerability is triggered via local filesystem operations and requires no special privileges beyond filesystem write access. An attacker with local access can trigger the leak repeatedly through copy_file_range() calls, leading to memory exhaustion and denial of service. A fix has been identified in the kernel source by ensuring deallocs are always run on copy-on-write completion.
Affected products
- Linux Linux kernel 6.12.94 and potentially other versions
Timeline
- 2026-09-11: disclosed