CVE-2026-97926
CVE CVE-2026-97926EUVD EUVD-2026-86780Published 2026-09-25T10:22:44.000ZLast changed 2026-09-25T14:41:38.000ZCVSS 7.0
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ufs: validate cylinder group metadata before caching it ufs_read_cylinder() copies the cylinder group index and the rotor positions straight from the on-disk group and caches them without any check: ucpi->c_cgx = fs32_to_cpu(sb, ucg->cg_cgx); ucpi->c_rotor = fs32_to_cpu(sb, ucg->cg_rotor); ucpi->c_frotor = fs32_to_cpu(sb, ucg->cg_frotor); ucpi->c_irotor = fs32_to_cpu(sb, ucg->cg_irotor); They are then used as indices during allocation and free: - c_cgx indexes the cylinder summary array as UFS_SB(sb)->fs_cs(ucpi->c_cgx), so a value past s_ncg writes a 32 bit count outside the s_csp allocation. - c_frotor becomes a bitmap scan start, start = c_frotor >> 3, and then length = ((s_fpg + 7) >> 3) - start. A start beyond the block bitmap wraps the unsigned length to a huge value, so ubh_scanc() walks far past the cylinder group buffers. c_irotor drives the inode bitmap the same way. A crafted image can set any of these freely, turning an ordinary allocation into an out of bounds access. Reject a cylinder group whose recorded index does not match the group being read, or whose rotors fall outside the group, before the metadata is cached. Valid filesystems keep cg_cgx equal to the group number and the rotors within the group, so only malformed images are rejected.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 2.6.12; patch: 7.3-rc3; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <87b12dc360a002eb2d498aa4f01e84347019612d; patch: 6.12.111; patch: 6.18.53; patch: 0; patch: 7.2.7; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <abde9eb33106850dfa367ad3965d3588bb8558d5; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5902a95066883cf96fa15b2680694fc5dd0c7d11; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <c9d263be26806d388129fab8c6904bed197fc6af
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.