Impact
The flaw in the Linux kernel’s ocfs2 filesystem is an integer truncation that occurs when recomputing the directory cookie position on 32‑bit kernels. The 64‑bit `loff_t` value of `ctx->pos` is bit‑masked against a 32‑bit block‑size pattern, which zero‑extends to 64 bits and silently clears the high 32 bits of the position. When a directory larger than 4 GiB is read, the readdir routine resets the position back into the first 4 GiB block and re‑enumerates already‑returned entries, causing an endless loop that stalls directory operations.
Affected Systems
All Linux kernel installations using the ocfs2 filesystem are affected. Any machine that mounts an ocfs2 volume containing a directory that crosses the 4‑GiB boundary on a 32‑bit kernel is vulnerable. 64‑bit kernels are unaffected, as are systems that never use ocfs2 or that keep all ocfs2 directories below 4 GiB.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate risk. The EPSS score of less than 1 % shows vulnerability is not listed in the CISA KEV catalog. An attacker would need local access to a process that performs readdir on a large ocfs2 directory; the impact is a denial‑of‑service through high CPU consumption, with no privilege escalation or remote code execution possible.
OpenCVE Enrichment
Debian DSA