SB20260828132 - Reachable assertion in Linux kernel ocfs2
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Reachable assertion (CVE-ID: CVE-2026-80644)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an assertion misuse in ocfs2_journal_toggle_dirty() in fs/ocfs2/journal.c when mounting a crafted OCFS2 image with an invalid journal dinode. A local user can mount a specially crafted filesystem image to cause a denial of service.
The issue is triggered during mount teardown while mount is still in progress.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/12c32a7350b670aaaaf2e01583d8648ec0c9755c
- https://git.kernel.org/stable/c/3852478d34c7baa490ba9c7374ee901a56eea577
- https://git.kernel.org/stable/c/5b33f99f3e48465bd93219495381a5aef4fa967f
- https://git.kernel.org/stable/c/86509c5296fe46ad6bcdd83931a53c2c6b7913a8
- https://git.kernel.org/stable/c/a06eec15596e5801bad59ad16cd2bf4f0fa839a1
- https://git.kernel.org/stable/c/b460f8d01a12061853d02c8fb693fb42450acd7d
- https://git.kernel.org/stable/c/bf1d59cf2ac8a1730607ebaa0bc0dc6d00f197d0
- https://git.kernel.org/stable/c/c0438198c28b1d22c272751af5e717c11d9fa8dd