7.8

CVE-2026-72164

ocfs2: avoid moving extents to occupied clusters

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: avoid moving extents to occupied clusters

For non-auto OCFS2_IOC_MOVE_EXT operations, userspace supplies a physical
me_goal.  ocfs2_move_extent() initializes new_phys_cpos from that goal and
expects ocfs2_probe_alloc_group() to replace it with a free run in the
target block group.

The probe currently leaves *phys_cpos unchanged if the scan reaches the
end of the group without finding a free run.  An occupied goal at the last
bit can therefore survive the probe and be passed to
__ocfs2_move_extent(), which copies file data into a cluster still owned
by another inode before the bitmap is updated.

When the probe does find a free run, it also subtracts move_len from the
ending bit.  The start of an N-bit run ending at i is i - N + 1, so the
current calculation can report the bit immediately before the free run.

Clear *phys_cpos before scanning and use the correct free-run start. 
Callers already treat a zero result as -ENOSPC, so failed probes no longer
continue with an occupied caller-controlled goal.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e6b5859cccfa0fec02f3c5b1069481efc7186f47
Version < 3112afebf2a76e522fbaabcbb0c47aafbdc35932
Status affected
Version e6b5859cccfa0fec02f3c5b1069481efc7186f47
Version < 35486b291b8fbde6c4d0b1c79e565c6260d3329d
Status affected
Version e6b5859cccfa0fec02f3c5b1069481efc7186f47
Version < 19f7b04924b20b81dabbeed19d5542792ba5b6d6
Status affected
Version e6b5859cccfa0fec02f3c5b1069481efc7186f47
Version < e281d892ce5870a50fdc718cb3bfc3dd5b62c728
Status affected
Version e6b5859cccfa0fec02f3c5b1069481efc7186f47
Version < 0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e
Status affected
Version e6b5859cccfa0fec02f3c5b1069481efc7186f47
Version < d5d5a21fb33cd9b963aea99da81e4dacd452cd95
Status affected
Version e6b5859cccfa0fec02f3c5b1069481efc7186f47
Version < 4d1953d3aeb4a7f6623083e1839068ee1c157db2
Status affected
Version e6b5859cccfa0fec02f3c5b1069481efc7186f47
Version < 22920541c35a9f23f219038ba5874c843a7c4419
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.0
Status affected
Version 0
Version < 3.0
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3112afebf2a76e522fbaabcbb0c47aafbdc35932
https://git.kernel.org/stable/c/35486b291b8fbde6c4d0b1c79e565c6260d3329d
https://git.kernel.org/stable/c/19f7b04924b20b81dabbeed19d5542792ba5b6d6
https://git.kernel.org/stable/c/e281d892ce5870a50fdc718cb3bfc3dd5b62c728
https://git.kernel.org/stable/c/0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e
https://git.kernel.org/stable/c/d5d5a21fb33cd9b963aea99da81e4dacd452cd95
https://git.kernel.org/stable/c/4d1953d3aeb4a7f6623083e1839068ee1c157db2
https://git.kernel.org/stable/c/22920541c35a9f23f219038ba5874c843a7c4419