SB20260905136 - Reachable assertion in Linux kernel ocfs2
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Reachable assertion (CVE-ID: CVE-2026-80809)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to missing metadata reservation in the OCFS2 extended attribute allocation code when setting a large extended attribute value on a fragmented filesystem for a file that already has an external extended attribute block. A local user can set a large extended attribute value to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04ba24bce61c917b5b3009f0db470cbb72e26a0d
- https://git.kernel.org/stable/c/0cdc7dde00ec63ac714271fa8b2918d630b8da1a
- https://git.kernel.org/stable/c/50f0cbec45b0f3fd7e1263d01916518dbf31eb3f
- https://git.kernel.org/stable/c/6176313622e34fa3e2b66b9d0682d1e1c6b365c5
- https://git.kernel.org/stable/c/6a009f1e61b11d9e23d3c5aa1dacfb010945da45
- https://git.kernel.org/stable/c/743ac908282ac97ef6e73ac3a92df2cc8ecb7479
- https://git.kernel.org/stable/c/a3ccb57086dd7652d5ecb826486144198a98a8e9
- https://git.kernel.org/stable/c/b4663405ae29d36011cd712d243456f3f9ab700d
- https://git.kernel.org/stable/c/b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec