Impact
This vulnerability exists in the Linux kernel’s OCFS2 filesystem. A corrupted orphan slot within a dirty inode can be used before it is validated, allowing the kernel to index memory locations outside of the allocated orphan‑wipe or system‑inode cache area. The unchecked slot value produces an out‑of‑bounds kernel memory access, which can trigger a use‑after‑free or arbitrary memory corruption. An attacker who can supply such a corrupted inode could cause a kernel panic or execute code with elevated privileges.
Affected Systems
The flaw affects any Linux distribution that uses the kernel with an unpatched OCFS2 implementation. No specific vendor or version list is provided in the CNA data, so the vulnerability applies broadly across all Linux kernels that include OCFS2 without the patch that validates orphan slots during inode read.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of < 1% suggests that exploitation is currently expected to be rare, yet the flaw remains present in many systems that lack the patch. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an attacker to supply or manipulate a corrupted OCFS2 inode, which is a local privilege escalation or kernel exploitation scenario. Systems that expose OCFS2 to untrusted users or accept third‑party OCFS2 images are at relatively higher risk.
OpenCVE Enrichment