8.8

CVE-2026-72160

ocfs2: reject dinodes with non-canonical i_mode type

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: reject dinodes with non-canonical i_mode type

Patch series "ocfs2: harden inode validators against forged metadata", v2.

This series adds three structural checks to OCFS2 dinode validation so
malformed on-disk fields are rejected before ocfs2_populate_inode() copies
them into the in-core inode.

The checks cover:

  - i_mode values whose type bits do not name a canonical POSIX file
    type;
  - non-device dinodes whose id1.dev1.i_rdev field is non-zero; and
  - non-inline dinodes that claim non-zero i_size while i_clusters is
    zero, covering directories unconditionally and regular files on
    non-sparse volumes.

The normal read path reports these through ocfs2_error(), matching the
existing suballoc-slot, inline-data, chain-list, and refcount checks.  The
online filecheck path uses the same structural predicates but keeps its
own reporting contract, returning OCFS2_FILECHECK_ERR_INVALIDINO instead
of calling ocfs2_error().


This patch (of 3):

ocfs2_validate_inode_block() currently accepts any non-zero i_mode value. 
ocfs2_populate_inode() then copies that mode verbatim into inode->i_mode
and dispatches on i_mode & S_IFMT to the file/dir/symlink/special_file
iops; an unrecognised type falls through to ocfs2_special_file_iops and
init_special_inode().

Reject dinodes whose type bits do not name one of the seven canonical
POSIX file types.  Use fs_umode_to_ftype(), the same generic file-type
conversion helper OCFS2 already uses for directory entries, so the
accepted inode type set matches the kernel file-type vocabulary instead of
open-coding a local switch.

Apply the same structural check to the online filecheck read path. 
filecheck keeps its own error namespace, so it reports malformed i_mode
through the filecheck logger and OCFS2_FILECHECK_ERR_INVALIDINO instead of
calling ocfs2_error(), but it must not allow a malformed dinode to proceed
into ocfs2_populate_inode().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b657c95c11088d77fc1bfc9c84d940f778bf9d12
Version < 2e3aac33988ef4e4170141db8e995693ea38357c
Status affected
Version b657c95c11088d77fc1bfc9c84d940f778bf9d12
Version < fb024ea29f6cb1f01745e5f2e31646f3acb9aa6f
Status affected
Version b657c95c11088d77fc1bfc9c84d940f778bf9d12
Version < 157d31ef45038d89cd19620105e082d43c8e41e0
Status affected
Version b657c95c11088d77fc1bfc9c84d940f778bf9d12
Version < a5b555bcabbb0aff8745ad181768eaf9d964c1ee
Status affected
Version b657c95c11088d77fc1bfc9c84d940f778bf9d12
Version < 82afe13558354390d8a592a5334d5f4fd72c0e5c
Status affected
Version b657c95c11088d77fc1bfc9c84d940f778bf9d12
Version < 4db3b6a2a8ecf2a89d26a4090ace4072c6fad050
Status affected
Version b657c95c11088d77fc1bfc9c84d940f778bf9d12
Version < b858f2d57cfc9d57ce61b86051d603dc0ebccd40
Status affected
Version b657c95c11088d77fc1bfc9c84d940f778bf9d12
Version < 5366a017099c6a3c443be908a05f26fd72af12a1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.29
Status affected
Version 0
Version < 2.6.29
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.474
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2e3aac33988ef4e4170141db8e995693ea38357c
https://git.kernel.org/stable/c/fb024ea29f6cb1f01745e5f2e31646f3acb9aa6f
https://git.kernel.org/stable/c/157d31ef45038d89cd19620105e082d43c8e41e0
https://git.kernel.org/stable/c/a5b555bcabbb0aff8745ad181768eaf9d964c1ee
https://git.kernel.org/stable/c/82afe13558354390d8a592a5334d5f4fd72c0e5c
https://git.kernel.org/stable/c/4db3b6a2a8ecf2a89d26a4090ace4072c6fad050
https://git.kernel.org/stable/c/b858f2d57cfc9d57ce61b86051d603dc0ebccd40
https://git.kernel.org/stable/c/5366a017099c6a3c443be908a05f26fd72af12a1