Executive brief
The OCFS2 filesystem driver in the Linux kernel did not validate inode metadata fields when reading file structures from disk. A maliciously crafted or corrupted OCFS2 filesystem could trigger a use-after-free memory error during file deletion operations, potentially leading to kernel crash or arbitrary code execution on affected systems.
Technical details
The vulnerability is a use-after-free bug in the OCFS2 filesystem's DIO (Direct I/O) orphan slot handling. The root cause is that the dinode validator (ocfs2_validate_inode_block) did not check whether the i_dio_orphaned_slot field falls within the valid filesystem slot range before allowing the inode to be loaded into memory. When an inode with an out-of-range slot value is accessed during orphan recovery, ocfs2_del_inode_from_orphan() dereferences an invalid cache pointer, triggering a KASAN slab-use-after-free error. The attack requires a malformed OCFS2 filesystem image (corrupted dinode at offset 0xa1), which can be supplied as a mounted volume. The fix adds validation in ocfs2_validate_inode_block to reject dinodes with OCFS2_DIO_ORPHANED_FL flag set if i_dio_orphaned_slot exceeds max_slots.
Affected products
- Linux Linux kernel multiple versions through 6.9 and 7.x
Timeline
- 2026-08-03: other: Patch submitted by ZhengYuan Huang
- 2026-08-13: patched: Merged upstream in commit bb88131c9831075b8dc08cdd375743e5d44c7ca2
- 2026-09-14: patched: Backported to stable kernel branches via commit 418e0ae42fa769d354b15e62c01a00413024755b
- 2026-09-17: disclosed