Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-53027
Published: June 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of attribute segment run loading in attr_data_get_block_locked() when processing compressed or sparse attributes with frame-aligned clusters. A local user can trigger the affected code path to cause a denial of service.
The issue is triggered when vcn is rounded down to the frame start and vcn and vcn0 reside in different attribute segments.
Affected software
Debian Linux
Ubuntu
linux (Debian package)
linux (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure (Ubuntu package)
linux-aws (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-53027
linux (Debian package) - update to 6.12.96-1
linux (Ubuntu package) - addressed in versions 7.0.0-28.28, 7.0.0-28.28.1, 7.0.0-1003.4, 7.0.0-1008.8
linux-ibm (Ubuntu package) - addressed in versions 7.0.0-1008.8, 7.0.0-1010.10
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1009.9
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16
External References
Related Security Bulletins
- Improper Check or Handling of Exceptional Conditions in Linux kernel ntfs3
- Ubuntu update for linux-oem-7.0
- Ubuntu update for linux
- Debian update for linux
- Ubuntu update for linux-ibm
- Ubuntu update for linux-azure
- Ubuntu update for linux-aws
- Ubuntu update for linux-nvidia-bos
- Ubuntu update for linux-nvidia