7
CVE-2026-97926
- EPSS 0.15%
- Veröffentlicht 25.09.2026 10:22:44
- Zuletzt bearbeitet 03.10.2026 11:18:10
- Erkennungen
ufs: validate cylinder group metadata before caching it
In the Linux kernel, the following vulnerability has been resolved:
ufs: validate cylinder group metadata before caching it
ufs_read_cylinder() copies the cylinder group index and the rotor
positions straight from the on-disk group and caches them without any
check:
ucpi->c_cgx = fs32_to_cpu(sb, ucg->cg_cgx);
ucpi->c_rotor = fs32_to_cpu(sb, ucg->cg_rotor);
ucpi->c_frotor = fs32_to_cpu(sb, ucg->cg_frotor);
ucpi->c_irotor = fs32_to_cpu(sb, ucg->cg_irotor);
They are then used as indices during allocation and free:
- c_cgx indexes the cylinder summary array as
UFS_SB(sb)->fs_cs(ucpi->c_cgx), so a value past s_ncg writes a 32
bit count outside the s_csp allocation.
- c_frotor becomes a bitmap scan start, start = c_frotor >> 3, and
then length = ((s_fpg + 7) >> 3) - start. A start beyond the block
bitmap wraps the unsigned length to a huge value, so ubh_scanc()
walks far past the cylinder group buffers. c_irotor drives the
inode bitmap the same way.
A crafted image can set any of these freely, turning an ordinary
allocation into an out of bounds access.
Reject a cylinder group whose recorded index does not match the group
being read, or whose rotors fall outside the group, before the metadata
is cached. Valid filesystems keep cg_cgx equal to the group number and
the rotors within the group, so only malformed images are rejected.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
88cccb6beba136b73f0caf80e59457e1b3c0ca1e
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
f560a9e33365c460827c735fd86435f9213f1aed
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
e4c5cc9688c3e69d07d888853388549ae26c0521
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
58c0c414b2b8d099d33da494a354fa836ca6c10b
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
5902a95066883cf96fa15b2680694fc5dd0c7d11
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
87b12dc360a002eb2d498aa4f01e84347019612d
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
abde9eb33106850dfa367ad3965d3588bb8558d5
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
c9d263be26806d388129fab8c6904bed197fc6af
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.12
Status
affected
Version
0
Version <
2.6.12
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.038 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/5902a95066883cf96fa15b2680694fc5dd0c7d11
https://git.kernel.org/stable/c/87b12dc360a002eb2d498aa4f01e84347019612d
https://git.kernel.org/stable/c/abde9eb33106850dfa367ad3965d3588bb8558d5
https://git.kernel.org/stable/c/c9d263be26806d388129fab8c6904bed197fc6af
https://git.kernel.org/stable/c/58c0c414b2b8d099d33da494a354fa836ca6c10b
https://git.kernel.org/stable/c/88cccb6beba136b73f0caf80e59457e1b3c0ca1e
https://git.kernel.org/stable/c/e4c5cc9688c3e69d07d888853388549ae26c0521
https://git.kernel.org/stable/c/f560a9e33365c460827c735fd86435f9213f1aed