Impact
In the Linux kernel, OCFS2 lacks proper validation of external extended attribute (xattr) metadata when reading. Specifically, ocfs2_validate_xattr_block does not ensure that non-indexed blocks’ header counts and offsets fit within the block, and indexed buckets skip bounds checks after ECC verification. This omission allows a corrupted xattr block to reference out‑of-range entry arrays or name/value offsets, which can trigger a use‑after‑free and potentially arbitrary kernel memory corruption. The issue was demonstrated by a KASAN report showing a read past the end of an xattr entry array during listxattr. Such memory corruption could be leveraged by an attacker to inject code or gain elevated privileges.
Affected Systems
The vulnerability affects the Linux operating system and its kernel implementation of the OCFS2 filesystem. No specific kernel version ranges are listed in the advisory, so any installation relying on an unpatched OCFS2 module may be susceptible.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high‑severity flaw. The EPSS score of less than 1% indicates a very low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, an attacker with the ability to craft or modify external xattr entries on an OCFS2 volume—which may be possible in a local or networked environment—could trigger the out‑of‑bounds read and potentially execute arbitrary code. The lack of a bounds check makes the issue exploitable with relatively simple privilege without needing additional system compromise. Based on the description, it is inferred that the attacker would need the ability to manipulate external xattr entries on an OCFS2 volume to trigger the flaw.
OpenCVE Enrichment