7

CVE-2026-97926

ufs: validate cylinder group metadata before caching it

In the Linux kernel, the following vulnerability has been resolved:

ufs: validate cylinder group metadata before caching it

ufs_read_cylinder() copies the cylinder group index and the rotor
positions straight from the on-disk group and caches them without any
check:

	ucpi->c_cgx    = fs32_to_cpu(sb, ucg->cg_cgx);
	ucpi->c_rotor  = fs32_to_cpu(sb, ucg->cg_rotor);
	ucpi->c_frotor = fs32_to_cpu(sb, ucg->cg_frotor);
	ucpi->c_irotor = fs32_to_cpu(sb, ucg->cg_irotor);

They are then used as indices during allocation and free:

  - c_cgx indexes the cylinder summary array as
    UFS_SB(sb)->fs_cs(ucpi->c_cgx), so a value past s_ncg writes a 32
    bit count outside the s_csp allocation.

  - c_frotor becomes a bitmap scan start, start = c_frotor >> 3, and
    then length = ((s_fpg + 7) >> 3) - start. A start beyond the block
    bitmap wraps the unsigned length to a huge value, so ubh_scanc()
    walks far past the cylinder group buffers. c_irotor drives the
    inode bitmap the same way.

A crafted image can set any of these freely, turning an ordinary
allocation into an out of bounds access.

Reject a cylinder group whose recorded index does not match the group
being read, or whose rotors fall outside the group, before the metadata
is cached. Valid filesystems keep cg_cgx equal to the group number and
the rotors within the group, so only malformed images are rejected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 88cccb6beba136b73f0caf80e59457e1b3c0ca1e
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < f560a9e33365c460827c735fd86435f9213f1aed
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < e4c5cc9688c3e69d07d888853388549ae26c0521
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 58c0c414b2b8d099d33da494a354fa836ca6c10b
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 5902a95066883cf96fa15b2680694fc5dd0c7d11
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 87b12dc360a002eb2d498aa4f01e84347019612d
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < abde9eb33106850dfa367ad3965d3588bb8558d5
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < c9d263be26806d388129fab8c6904bed197fc6af
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.038
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5902a95066883cf96fa15b2680694fc5dd0c7d11
https://git.kernel.org/stable/c/87b12dc360a002eb2d498aa4f01e84347019612d
https://git.kernel.org/stable/c/abde9eb33106850dfa367ad3965d3588bb8558d5
https://git.kernel.org/stable/c/c9d263be26806d388129fab8c6904bed197fc6af
https://git.kernel.org/stable/c/58c0c414b2b8d099d33da494a354fa836ca6c10b
https://git.kernel.org/stable/c/88cccb6beba136b73f0caf80e59457e1b3c0ca1e
https://git.kernel.org/stable/c/e4c5cc9688c3e69d07d888853388549ae26c0521
https://git.kernel.org/stable/c/f560a9e33365c460827c735fd86435f9213f1aed