Impact
The Linux kernel’s ocfs2 file‑system component performs validation of indexed‑directory blocks but the loop that walks the entry list uses counters that are not bounded. A crafted on‑disk image can set the de_num_used field to the maximum 16‑bit value, causing the kernel to read entries far beyond the allocated 4 KB block during a directory search. This out‑of‑bounds read can be triggered by any filesystem lookup such as stat, open, or path resolution on a corrupted directory, leaking kernel memory to any process with access to the file system. The flaw is a classic read overflow (CWE‑125).
Affected Systems
All Linux kernel releases released before the commit that added bounds checking (775c17386a6f) are affected. Any system that mounts an OCFS2 file system containing a corrupted indexed directory is at risk. The vulnerability applies to the generic Linux kernel (vendor Linux) and its supported derivatives that contain the ocfs2 module.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is rated critical, yet the EPSS score of <1% indicates that exploitation is unlikely at present. The flaw is local: an attacker must supply a crafted OCFS2 file‑system image to the kernel; no network‑based attack vector exists. Exploitation yields an out‑of‑bounds read of kernel memory, providing information disclosure but not code execution or persistence. The advisory is not listed in the CISA KEV catalog, and no public exploits are known.
OpenCVE Enrichment
Debian DSA