Impact
The flaw resides in the OCFS2 filesystem module of the Linux kernel. During the validation of refcount blocks, the fields rl_used and rl_count are not bounded against the on‑disk record capacity, allowing a crafted block with rl_used set to 0xffff to cause the code to walk far beyond the 4 KiB boundary. This exceeds the block’s size and results in an out‑of‑bounds read followed by an out‑of‑bounds memmove that can copy up to roughly one megabyte from an invalid memory area. The corruption extends into the kernel address space and can lead to privilege escalation or arbitrary code execution. Based on the description, it is inferred that the attacker must be able to execute local privileged actions such as mounting a crafted OCFS2 image or performing raw writes to the underlying block device.
Affected Systems
This vulnerability affects all Linux kernel implementations that include the OCFS2 filesystem module. The flaw is present in any kernel version that ships with the default OCFS2 implementation until a patch is applied. Both Linux distributions and the upstream kernel contain the vulnerable code. No specific version constraints are enumerated in the CNA data; therefore any kernel that supports OCFS2 can be impacted, regardless of the major or minor release number.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is less than 1%, implying a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attacker model is local; CAP_SYS_ADMIN is required to mount a crafted OCFS2 image or to perform raw writes to the block device. It is inferred that the exploit relies on a user with administrative privileges on the host. The vulnerability is not reachable over the network and therefore depends on local access. If triggered, the out‑of‑bounds read and write during refcount handling can corrupt kernel memory, potentially enabling privilege escalation or arbitrary code execution.
OpenCVE Enrichment
Debian DSA