Out-of-bounds read in Linux kernel - CVE-2026-63796
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the ocfs2 group descriptor bitmap handling in fs/ocfs2/suballoc.c when processing a crafted group bitmap descriptor. A local user can provide a descriptor with oversized bg_size or bg_bits values to cause a denial of service.
Exploitation requires access to a malicious ocfs2 filesystem image or on-disk metadata.
Affected software
openEuler
Ubuntu
bpftool
python3-perf-debuginfo
python3-perf
perf-debuginfo
perf
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-source
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
kernel
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-63796
bpftool - update to 5.10.0-328.0.0.229
python3-perf-debuginfo - update to 5.10.0-328.0.0.229
python3-perf - update to 5.10.0-328.0.0.229
perf-debuginfo - update to 5.10.0-328.0.0.229
perf - update to 5.10.0-328.0.0.229
kernel-tools-devel - update to 5.10.0-328.0.0.229
kernel-tools-debuginfo - update to 5.10.0-328.0.0.229
kernel-tools - update to 5.10.0-328.0.0.229
kernel-source - update to 5.10.0-328.0.0.229
kernel-headers - update to 5.10.0-328.0.0.229
kernel-devel - update to 5.10.0-328.0.0.229
kernel-debugsource - update to 5.10.0-328.0.0.229
kernel-debuginfo - update to 5.10.0-328.0.0.229
bpftool-debuginfo - update to 5.10.0-328.0.0.229
kernel - update to 5.10.0-328.0.0.229
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/296c6a42b1174395935ca4cfe8f393e37b698d54
- https://git.kernel.org/stable/c/336340a0f8a141df8a4eb21a5a86f8ffb87769f6
- https://git.kernel.org/stable/c/4cd57ebee395041099fcdfcabb00749ce38d8b27
- https://git.kernel.org/stable/c/8f9903b0cdbb3155a8899410330b4b4d583a7a5c
- https://git.kernel.org/stable/c/99c21e7263248c3f084756bfae08163cc5d6c62f
- https://git.kernel.org/stable/c/9bd541e09dffff27e5bec0f9f45b0228173a5375
- https://git.kernel.org/stable/c/c5a125eadba05ba421c4b55e68da22b4a40d32b4
- https://git.kernel.org/stable/c/d2cd59fa848f9f13796ef214d3b1b5ca9a3fe21e