๐Ÿ” CVE Alert

CVE-2026-72164

UNKNOWN 0.0

ocfs2: avoid moving extents to occupied clusters

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ocfs2: avoid moving extents to occupied clusters For non-auto OCFS2_IOC_MOVE_EXT operations, userspace supplies a physical me_goal. ocfs2_move_extent() initializes new_phys_cpos from that goal and expects ocfs2_probe_alloc_group() to replace it with a free run in the target block group. The probe currently leaves *phys_cpos unchanged if the scan reaches the end of the group without finding a free run. An occupied goal at the last bit can therefore survive the probe and be passed to __ocfs2_move_extent(), which copies file data into a cluster still owned by another inode before the bitmap is updated. When the probe does find a free run, it also subtracts move_len from the ending bit. The start of an N-bit run ending at i is i - N + 1, so the current calculation can report the bit immediately before the free run. Clear *phys_cpos before scanning and use the correct free-run start. Callers already treat a zero result as -ENOSPC, so failed probes no longer continue with an occupied caller-controlled goal.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
e6b5859cccfa0fec02f3c5b1069481efc7186f47 < 3112afebf2a76e522fbaabcbb0c47aafbdc35932 e6b5859cccfa0fec02f3c5b1069481efc7186f47 < 35486b291b8fbde6c4d0b1c79e565c6260d3329d e6b5859cccfa0fec02f3c5b1069481efc7186f47 < 19f7b04924b20b81dabbeed19d5542792ba5b6d6 e6b5859cccfa0fec02f3c5b1069481efc7186f47 < e281d892ce5870a50fdc718cb3bfc3dd5b62c728 e6b5859cccfa0fec02f3c5b1069481efc7186f47 < 0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e e6b5859cccfa0fec02f3c5b1069481efc7186f47 < d5d5a21fb33cd9b963aea99da81e4dacd452cd95 e6b5859cccfa0fec02f3c5b1069481efc7186f47 < 4d1953d3aeb4a7f6623083e1839068ee1c157db2 e6b5859cccfa0fec02f3c5b1069481efc7186f47 < 22920541c35a9f23f219038ba5874c843a7c4419
Linux / Linux
3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3112afebf2a76e522fbaabcbb0c47aafbdc35932 git.kernel.org: https://git.kernel.org/stable/c/35486b291b8fbde6c4d0b1c79e565c6260d3329d git.kernel.org: https://git.kernel.org/stable/c/19f7b04924b20b81dabbeed19d5542792ba5b6d6 git.kernel.org: https://git.kernel.org/stable/c/e281d892ce5870a50fdc718cb3bfc3dd5b62c728 git.kernel.org: https://git.kernel.org/stable/c/0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e git.kernel.org: https://git.kernel.org/stable/c/d5d5a21fb33cd9b963aea99da81e4dacd452cd95 git.kernel.org: https://git.kernel.org/stable/c/4d1953d3aeb4a7f6623083e1839068ee1c157db2 git.kernel.org: https://git.kernel.org/stable/c/22920541c35a9f23f219038ba5874c843a7c4419