CVE-2026-74349
CVE CVE-2026-74349EUVD EUVD-2026-59496Published 2026-08-15T05:58:36.000ZLast changed 2026-08-17T05:46:12.000ZCVSS 7.1
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shorter than a cluster ocfs2_trim_mainbm() trims the global bitmap in cluster units, but its too-short range validation only checks sb->s_blocksize. On filesystems with a cluster size larger than the block size, a FITRIM range that is at least one block but shorter than one cluster is accepted and shifted down to len == 0. The later start + len - 1 and len -= ... arithmetic then underflows and can drive trimming past the requested range. Reject ranges shorter than s_clustersize instead. That preserves the existing -EINVAL behavior for requests that cannot discard even one allocation unit and keeps zero-cluster trims out of the group walk.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux aa89762c54800208d5afdcd8e6bf124818f17fe0 <ca1afd88f5eaaff9168e1466e5401385edf59543; patch: 6.12.97; patch: 6.18.40; aa89762c54800208d5afdcd8e6bf124818f17fe0 <06c0a0431b9856506fcd9b2c1b0c6136567d756d; aa89762c54800208d5afdcd8e6bf124818f17fe0 <d903d59c0315f59bdf0214b4f13d71c9feb2c45c; patch: 5.10.261; patch: 6.1.178; patch: 7.1.5; aa89762c54800208d5afdcd8e6bf124818f17fe0 <441abb77222f155e8d931dbabb465466db01cfd7; patch: 0; 3.14; aa89762c54800208d5afdcd8e6bf124818f17fe0 <346314bb0cc2fc52b50b73d6ecc62e0217455c2e; aa89762c54800208d5afdcd8e6bf124818f17fe0 <2c13e02592b918be7725ab5965e01ef4e46c4b57; patch: 7.2; patch: 5.15.212; aa89762c54800208d5afdcd8e6bf124818f17fe0 <3fa7139b5f42731a61f78c42433adae13f9adc21; aa89762c54800208d5afdcd8e6bf124818f17fe0 <e652d0f5108e447b22da4249bcd23dd1b63c73dd; patch: 6.6.145
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.