Linux Kernel Vulnerability in OCFS2 File System Affecting Multiple Users
CVE-2026-93258

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-93258?

A vulnerability in the OCFS2 file system within the Linux kernel has been identified due to the improper handling of bad inodes. Specifically, the use of 'make_bad_inode()' can reset the inode type to S_IFREG, which may lead to confusion during active Virtual File System (VFS) lookups. This can result in potential vulnerabilities where the VFS_BUG_ON_INODE() function is triggered, indicating an unexpected inode type during critical operations. The reversion of the previous commit addressing inode validation failure ensures that directory inodes are correctly managed, maintaining file system integrity and security.

Affected Version(s)

Linux 58b6fcd2ab34399258dc509f701d0986a8e0bcaa < 0e7459abff46e28e64367057038ef8607e63f599

Linux 58b6fcd2ab34399258dc509f701d0986a8e0bcaa

Linux 6.19

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.