-

CVE-2026-80809

Medienbericht

ocfs2: fix missing metadata reservation for large xattrs

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix missing metadata reservation for large xattrs

[BUG]
lsetxattr() panics the kernel when setting a large xattr value on a
fragmented filesystem where the file already has an external xattr
block.

[CAUSE]
ocfs2_calc_xattr_set_need() never reserves metadata blocks for a new
xattr value's extent tree when the file already has an external xattr
block. The not_found path leaves meta_add at zero, so meta_ac is NULL
when ocfs2_xattr_extend_allocation() runs.

A new value root has room for a single extent record. On a fragmented
filesystem, the allocator cannot satisfy the xattr value in one
contiguous run, so each non-contiguous run requires its own extent
record. When the value root's extent list is full and meta_ac is NULL,
ocfs2_add_clusters_in_btree() returns RESTART_META, and
ocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META).

[FIX]
The case where no xattr block exists yet already calls
ocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree
metadata. Add the same reservation to the case where an xattr block
already exists, making the two cases consistent.

Replace the BUG_ON with a -ENOSPC return so that if RESTART_META is
returned despite the reservation, the error propagates to userspace
instead of panicking the kernel.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a78f9f4668949a6588b8872f162e86685c63d023
Version < 743ac908282ac97ef6e73ac3a92df2cc8ecb7479
Status affected
Version a78f9f4668949a6588b8872f162e86685c63d023
Version < 04ba24bce61c917b5b3009f0db470cbb72e26a0d
Status affected
Version a78f9f4668949a6588b8872f162e86685c63d023
Version < b4663405ae29d36011cd712d243456f3f9ab700d
Status affected
Version a78f9f4668949a6588b8872f162e86685c63d023
Version < 6a009f1e61b11d9e23d3c5aa1dacfb010945da45
Status affected
Version a78f9f4668949a6588b8872f162e86685c63d023
Version < b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec
Status affected
Version a78f9f4668949a6588b8872f162e86685c63d023
Version < 6176313622e34fa3e2b66b9d0682d1e1c6b365c5
Status affected
Version a78f9f4668949a6588b8872f162e86685c63d023
Version < a3ccb57086dd7652d5ecb826486144198a98a8e9
Status affected
Version a78f9f4668949a6588b8872f162e86685c63d023
Version < 50f0cbec45b0f3fd7e1263d01916518dbf31eb3f
Status affected
Version a78f9f4668949a6588b8872f162e86685c63d023
Version < 0cdc7dde00ec63ac714271fa8b2918d630b8da1a
Status affected
Version 92f61d8a31e270f9391e7bcc0ac638bd4262a8e0
Status affected
Version 2.6.34.2
Version < 2.6.35
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.35
Status affected
Version 0
Version < 2.6.35
Status unaffected
Version <= 5.10.*
Version 5.10.267
Status unaffected
Version <= 5.15.*
Version 5.15.218
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/743ac908282ac97ef6e73ac3a92df2cc8ecb7479
https://git.kernel.org/stable/c/04ba24bce61c917b5b3009f0db470cbb72e26a0d
https://git.kernel.org/stable/c/b4663405ae29d36011cd712d243456f3f9ab700d
https://git.kernel.org/stable/c/6a009f1e61b11d9e23d3c5aa1dacfb010945da45
https://git.kernel.org/stable/c/b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec
https://git.kernel.org/stable/c/6176313622e34fa3e2b66b9d0682d1e1c6b365c5
https://git.kernel.org/stable/c/a3ccb57086dd7652d5ecb826486144198a98a8e9
https://git.kernel.org/stable/c/50f0cbec45b0f3fd7e1263d01916518dbf31eb3f
https://git.kernel.org/stable/c/0cdc7dde00ec63ac714271fa8b2918d630b8da1a