CVE-2026-72163
CVE CVE-2026-72163EUVD EUVD-2026-58921Published 2026-08-15T05:53:31.000ZLast changed 2026-08-17T05:09:24.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits [BUG] A direct write over unwritten extents can panic the kernel in ocfs2_assure_trans_credits() when the journal aborts during DIO completion. The crash is a general protection fault from a NULL pointer dereference. [CAUSE] ocfs2_dio_end_io_write() loops over a direct write's unwritten extents, marking each written under a single journal handle. If the journal aborts (for example after an I/O error) while the extent tree is being updated, the handle is left aborted with its transaction pointer cleared. The extent merge treats that failure as not critical and reports success, so the loop keeps using the handle. ocfs2_assure_trans_credits() reads the handle's remaining credits without first checking whether the handle is aborted, and that read dereferences the cleared transaction pointer. [FIX] A journal abort is recorded in the handle itself, so callers are expected to test the handle rather than rely on a returned error. Make ocfs2_assure_trans_credits() do that, as the other ocfs2 journal helpers already do, and return -EROFS when the handle is aborted.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 6.10; 5.15.162 <5.15.212; 5.10.221 <5.10.261; be346c1a6eeb49d8fda827d2a9522124c2f72f36 <253ed993e0b36997ec7b04c1ff76103b38241de2; patch: 6.6.145; patch: 5.10.261; a68b896aa56e435506453ec8835bc991ec3ae687 <2d80e9c56718435a9c9f5f24dbc954989aead579; patch: 0; patch: 7.2; be346c1a6eeb49d8fda827d2a9522124c2f72f36 <6ad7532a23bc94076efe9f1486dd7f7493c090ff; 9ea2d1c6789722d58ec191f14f9a02518d55b6b4 <7146d191dae3a8efdb957993fb61a55713186266; patch: 5.15.212; be346c1a6eeb49d8fda827d2a9522124c2f72f36 <f9ab30c96b0f00c20c6dac93681bdae3a033d229; be346c1a6eeb49d8fda827d2a9522124c2f72f36 <bd73971fad89d5ee4ea0ba9b92d2ea08733c4a64; patch: 7.1.5; 331d1079d58206ff7dc5518185f800b412f89bc6; patch: 6.18.40; 6.6.37 <6.6.145; 6.1.97 <6.1.178; patch: 6.1.178; 6.9.8 <6.10; patch: 6.12.97; 320273b5649bbcee87f9e65343077189699d2a7a <942b818b396c24c452681803ff291552317d2ef1; c05ffb693bfb42a48ef3ee88a55b57392984e111 <f14aaaa130356ee4adb44de947c098637c70df8f
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.