CVE-2026-63796 (GCVE-0-2026-63796)
Vulnerability from cvelistv5
Published
2026-07-19 12:02
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: reject oversized group bitmap descriptors
ocfs2_validate_gd_parent() only bounds bg_bits against the parent
allocator's chain geometry. A malicious descriptor can still claim a
bg_size/bg_bits pair that exceeds the bitmap bytes that physically fit in
the group descriptor block, so later bitmap scans and bit updates can run
past bg_bitmap.
Add a physical-cap check based on ocfs2_group_bitmap_size() for the parent
allocator type and reject descriptors whose bg_size or bg_bits exceed that
capacity. Keep the existing chain geometry check so both the on-disk
bitmap layout and the allocator metadata must agree before the descriptor
is used.
Validation reproduced this kernel report:
KASAN use-after-free in _find_next_bit+0x7f/0xc0
Read of size 8
Call trace:
dump_stack_lvl+0x66/0xa0 (?:?)
print_report+0xd0/0x630 (?:?)
_find_next_bit+0x7f/0xc0 (?:?)
srso_alias_return_thunk+0x5/0xfbef5 (?:?)
__virt_addr_valid+0x188/0x2f0 (?:?)
kasan_report+0xe4/0x120 (?:?)
ocfs2_find_max_contig_free_bits+0x35/0x70 (fs/ocfs2/suballoc.c:1375)
ocfs2_block_group_set_bits+0x472/0x4b0 (fs/ocfs2/suballoc.c:1457)
ocfs2_cluster_group_search+0x16b/0x440 (fs/ocfs2/suballoc.c:86)
ocfs2_bg_discontig_fix_result+0x1ef/0x230 (fs/ocfs2/suballoc.c:1786)
ocfs2_search_chain+0x8f8/0x10a0 (fs/ocfs2/suballoc.c:1886)
get_page_from_freelist+0x70e/0x2370 (?:?)
lock_release+0xc6/0x290 (?:?)
do_raw_spin_unlock+0x9a/0x100 (?:?)
kasan_unpoison+0x27/0x60 (?:?)
__bfs+0x147/0x240 (?:?)
get_page_from_freelist+0x83d/0x2370 (?:?)
ocfs2_claim_suballoc_bits+0x38c/0xe70 (fs/ocfs2/suballoc.c:96)
sched_domains_numa_masks_clear+0x70/0xd0 (?:?)
check_irq_usage+0xe8/0xb70 (?:?)
__ocfs2_claim_clusters+0x18d/0x4c0 (fs/ocfs2/suballoc.c:2497)
check_path+0x24/0x50 (?:?)
rcu_is_watching+0x20/0x50 (?:?)
check_prev_add+0xfd/0xd00 (?:?)
ocfs2_add_clusters_in_btree+0x17d/0x810 (fs/ocfs2/suballoc.c:?)
__folio_batch_add_and_move+0x1f5/0x3d0 (?:?)
ocfs2_add_inode_data+0xd9/0x120 (fs/ocfs2/suballoc.c:?)
filemap_add_folio+0x105/0x1f0 (?:?)
ocfs2_write_begin_nolock+0x29f7/0x2f80 (fs/ocfs2/suballoc.c:3043)
ocfs2_read_inode_block+0xb5/0x110 (fs/ocfs2/suballoc.c:?)
down_write+0xf5/0x180 (?:?)
ocfs2_write_begin+0x180/0x240 (fs/ocfs2/suballoc.c:?)
__mark_inode_dirty+0x758/0x9a0 (?:?)
inode_to_bdi+0x41/0x90 (?:?)
balance_dirty_pages_ratelimited_flags+0xf8/0x1d0 (?:?)
generic_perform_write+0x252/0x440 (?:?)
mnt_put_write_access_file+0x16/0x70 (?:?)
file_update_time_flags+0xe4/0x200 (?:?)
ocfs2_file_write_iter+0x80a/0x1320 (fs/ocfs2/suballoc.c:?)
lock_acquire+0x184/0x2f0 (?:?)
ksys_write+0xd2/0x170 (?:?)
apparmor_file_permission+0xf5/0x310 (?:?)
read_zero+0x8d/0x140 (?:?)
lock_is_held_type+0x8f/0x100 (?:?)
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: ccd979bdbce9fba8412beb3f1de68a9d0171b12c Version: ccd979bdbce9fba8412beb3f1de68a9d0171b12c Version: ccd979bdbce9fba8412beb3f1de68a9d0171b12c Version: ccd979bdbce9fba8412beb3f1de68a9d0171b12c Version: ccd979bdbce9fba8412beb3f1de68a9d0171b12c Version: ccd979bdbce9fba8412beb3f1de68a9d0171b12c Version: ccd979bdbce9fba8412beb3f1de68a9d0171b12c Version: ccd979bdbce9fba8412beb3f1de68a9d0171b12c |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ocfs2/suballoc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "336340a0f8a141df8a4eb21a5a86f8ffb87769f6",
"status": "affected",
"version": "ccd979bdbce9fba8412beb3f1de68a9d0171b12c",
"versionType": "git"
},
{
"lessThan": "296c6a42b1174395935ca4cfe8f393e37b698d54",
"status": "affected",
"version": "ccd979bdbce9fba8412beb3f1de68a9d0171b12c",
"versionType": "git"
},
{
"lessThan": "d2cd59fa848f9f13796ef214d3b1b5ca9a3fe21e",
"status": "affected",
"version": "ccd979bdbce9fba8412beb3f1de68a9d0171b12c",
"versionType": "git"
},
{
"lessThan": "c5a125eadba05ba421c4b55e68da22b4a40d32b4",
"status": "affected",
"version": "ccd979bdbce9fba8412beb3f1de68a9d0171b12c",
"versionType": "git"
},
{
"lessThan": "8f9903b0cdbb3155a8899410330b4b4d583a7a5c",
"status": "affected",
"version": "ccd979bdbce9fba8412beb3f1de68a9d0171b12c",
"versionType": "git"
},
{
"lessThan": "4cd57ebee395041099fcdfcabb00749ce38d8b27",
"status": "affected",
"version": "ccd979bdbce9fba8412beb3f1de68a9d0171b12c",
"versionType": "git"
},
{
"lessThan": "99c21e7263248c3f084756bfae08163cc5d6c62f",
"status": "affected",
"version": "ccd979bdbce9fba8412beb3f1de68a9d0171b12c",
"versionType": "git"
},
{
"lessThan": "9bd541e09dffff27e5bec0f9f45b0228173a5375",
"status": "affected",
"version": "ccd979bdbce9fba8412beb3f1de68a9d0171b12c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ocfs2/suballoc.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.16"
},
{
"lessThan": "2.6.16",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.260",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "2.6.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: reject oversized group bitmap descriptors\n\nocfs2_validate_gd_parent() only bounds bg_bits against the parent\nallocator\u0027s chain geometry. A malicious descriptor can still claim a\nbg_size/bg_bits pair that exceeds the bitmap bytes that physically fit in\nthe group descriptor block, so later bitmap scans and bit updates can run\npast bg_bitmap.\n\nAdd a physical-cap check based on ocfs2_group_bitmap_size() for the parent\nallocator type and reject descriptors whose bg_size or bg_bits exceed that\ncapacity. Keep the existing chain geometry check so both the on-disk\nbitmap layout and the allocator metadata must agree before the descriptor\nis used.\n\nValidation reproduced this kernel report:\nKASAN use-after-free in _find_next_bit+0x7f/0xc0\nRead of size 8\nCall trace:\n dump_stack_lvl+0x66/0xa0 (?:?)\n print_report+0xd0/0x630 (?:?)\n _find_next_bit+0x7f/0xc0 (?:?)\n srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n __virt_addr_valid+0x188/0x2f0 (?:?)\n kasan_report+0xe4/0x120 (?:?)\n ocfs2_find_max_contig_free_bits+0x35/0x70 (fs/ocfs2/suballoc.c:1375)\n ocfs2_block_group_set_bits+0x472/0x4b0 (fs/ocfs2/suballoc.c:1457)\n ocfs2_cluster_group_search+0x16b/0x440 (fs/ocfs2/suballoc.c:86)\n ocfs2_bg_discontig_fix_result+0x1ef/0x230 (fs/ocfs2/suballoc.c:1786)\n ocfs2_search_chain+0x8f8/0x10a0 (fs/ocfs2/suballoc.c:1886)\n get_page_from_freelist+0x70e/0x2370 (?:?)\n lock_release+0xc6/0x290 (?:?)\n do_raw_spin_unlock+0x9a/0x100 (?:?)\n kasan_unpoison+0x27/0x60 (?:?)\n __bfs+0x147/0x240 (?:?)\n get_page_from_freelist+0x83d/0x2370 (?:?)\n ocfs2_claim_suballoc_bits+0x38c/0xe70 (fs/ocfs2/suballoc.c:96)\n sched_domains_numa_masks_clear+0x70/0xd0 (?:?)\n check_irq_usage+0xe8/0xb70 (?:?)\n __ocfs2_claim_clusters+0x18d/0x4c0 (fs/ocfs2/suballoc.c:2497)\n check_path+0x24/0x50 (?:?)\n rcu_is_watching+0x20/0x50 (?:?)\n check_prev_add+0xfd/0xd00 (?:?)\n ocfs2_add_clusters_in_btree+0x17d/0x810 (fs/ocfs2/suballoc.c:?)\n __folio_batch_add_and_move+0x1f5/0x3d0 (?:?)\n ocfs2_add_inode_data+0xd9/0x120 (fs/ocfs2/suballoc.c:?)\n filemap_add_folio+0x105/0x1f0 (?:?)\n ocfs2_write_begin_nolock+0x29f7/0x2f80 (fs/ocfs2/suballoc.c:3043)\n ocfs2_read_inode_block+0xb5/0x110 (fs/ocfs2/suballoc.c:?)\n down_write+0xf5/0x180 (?:?)\n ocfs2_write_begin+0x180/0x240 (fs/ocfs2/suballoc.c:?)\n __mark_inode_dirty+0x758/0x9a0 (?:?)\n inode_to_bdi+0x41/0x90 (?:?)\n balance_dirty_pages_ratelimited_flags+0xf8/0x1d0 (?:?)\n generic_perform_write+0x252/0x440 (?:?)\n mnt_put_write_access_file+0x16/0x70 (?:?)\n file_update_time_flags+0xe4/0x200 (?:?)\n ocfs2_file_write_iter+0x80a/0x1320 (fs/ocfs2/suballoc.c:?)\n lock_acquire+0x184/0x2f0 (?:?)\n ksys_write+0xd2/0x170 (?:?)\n apparmor_file_permission+0xf5/0x310 (?:?)\n read_zero+0x8d/0x140 (?:?)\n lock_is_held_type+0x8f/0x100 (?:?)"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - OCFS2 registers `ocfs2_export_ops` and is commonly deployed on shared cluster storage exported via NFS; a remote NFS client write reaches `ocfs2_file_write_iter` \u2192 cluster allocation \u2192 the vulnerable bitmap scan without local shell access on the server.\nAC:L - Once a crafted group descriptor with oversized `bg_size`/`bg_bits` is on disk, a single file write reliably drives `ocfs2_find_max_contig_free_bits()` past `bg_bitmap`; the fix commit reproduced this deterministically under KASAN with no race or layout-dependent conditions.\nPR:L - Exploitation requires only write access to a file on the mounted OCFS2 volume (local unprivileged user) or equivalent NFS write credentials; mounting requires `CAP_SYS_ADMIN` but metadata planting on shared SAN/iSCSI LUNs is separate from the trigger privilege.\nUI:N - In the highest-impact scenario\u2014malicious group-descriptor metadata pre-placed on shared cluster storage already mounted in production\u2014the attacker triggers the bug with their own write and no additional victim action (mount, open, or click) is required at exploit time.\nS:U - The bug corrupts kernel heap memory during in-kernel filesystem allocation on the same host/NFS server; impact stays within the kernel\u2019s security authority and does not inherently cross VM, container, or IOMMU boundaries.\nC:H - Oversized `bg_bits` causes `_find_next_bit()` to read past the physical `bg_bitmap` region; the fix commit documents a KASAN use-after-free/out-of-bounds read, which is an arbitrary kernel memory read primitive under attacker-influenced scan bounds.\nI:H - The same inflated `bg_bits` drives `ocfs2_set_bit()` during `ocfs2_block_group_set_bits()`, enabling out-of-bounds writes in the group-descriptor buffer page that can be leveraged for heap corruption and control-flow hijacking.\nA:H - The reproduced KASAN fault in `_find_next_bit()` during cluster allocation on write demonstrates kernel memory corruption that causes oops/panic-level availability loss on affected nodes."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:01.192Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/336340a0f8a141df8a4eb21a5a86f8ffb87769f6"
},
{
"url": "https://git.kernel.org/stable/c/296c6a42b1174395935ca4cfe8f393e37b698d54"
},
{
"url": "https://git.kernel.org/stable/c/d2cd59fa848f9f13796ef214d3b1b5ca9a3fe21e"
},
{
"url": "https://git.kernel.org/stable/c/c5a125eadba05ba421c4b55e68da22b4a40d32b4"
},
{
"url": "https://git.kernel.org/stable/c/8f9903b0cdbb3155a8899410330b4b4d583a7a5c"
},
{
"url": "https://git.kernel.org/stable/c/4cd57ebee395041099fcdfcabb00749ce38d8b27"
},
{
"url": "https://git.kernel.org/stable/c/99c21e7263248c3f084756bfae08163cc5d6c62f"
},
{
"url": "https://git.kernel.org/stable/c/9bd541e09dffff27e5bec0f9f45b0228173a5375"
}
],
"title": "ocfs2: reject oversized group bitmap descriptors",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63796",
"datePublished": "2026-07-19T12:02:04.634Z",
"dateReserved": "2026-07-19T07:54:57.012Z",
"dateUpdated": "2026-08-17T04:51:01.192Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…