Linux Kernel Vulnerability in OCFS2 Filesystem by Oracle
CVE-2026-63796
What is CVE-2026-63796?
A vulnerability exists in the OCFS2 filesystem within the Linux kernel, where oversized group bitmap descriptors can lead to memory corruption. Specifically, the function ocfs2_validate_gd_parent() fails to adequately check that the size of the bitmap does not exceed the allocated memory space. This allows for potential unauthorized access and manipulation of data during bitmap scans and updates. To mitigate this risk, a physical capacity check has been implemented to ensure that descriptors conform to the expected limits, effectively preventing future exploitation.
Affected Version(s)
Linux ccd979bdbce9fba8412beb3f1de68a9d0171b12c < 336340a0f8a141df8a4eb21a5a86f8ffb87769f6
Linux ccd979bdbce9fba8412beb3f1de68a9d0171b12c < 296c6a42b1174395935ca4cfe8f393e37b698d54
Linux ccd979bdbce9fba8412beb3f1de68a9d0171b12c