SB20260424282 - Improper input validation in Linux kernel ext4
Published: April 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-31447)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in ext4 mount handling when mounting a crafted ext4 filesystem with bigalloc enabled and s_first_data_block set to a non-zero value. A local user can mount a specially crafted filesystem image to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3822743dc20386d9897e999dbb990befa3a5b3f8
- https://git.kernel.org/stable/c/3a926957cc95899ef88529710836edadc03c71a1
- https://git.kernel.org/stable/c/5ad6d994255e27a3254079dfb50ca861fc31f2d0
- https://git.kernel.org/stable/c/7b58c110b4e1f028eb38eec9ed3555e9be81c8b0
- https://git.kernel.org/stable/c/7d5b04290156c3fc316eecc86a4f9d201ab7d44a
- https://git.kernel.org/stable/c/ad1f6d608f33f59d21a3d025615d6786a6443998
- https://git.kernel.org/stable/c/b77de3fceafbb39f30e4ff5dc986f863d5456417
- https://git.kernel.org/stable/c/d787d3ae96648dc14a3b7ca8fde817177e82c1c7