PT-2026-43869 · Linux+2 · Linux Kernel+2
CVE-2026-46002
·
Published
2026-05-27
·
Updated
2026-08-25
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the ext2 filesystem where the
ext2 iget() function fails to reject inodes that have a link count i nlink of zero while maintaining a valid mode and a zero deletion time i dtime. This specific combination typically indicates filesystem corruption, as legitimate deletions should either clear the mode or set the deletion time. A crafted image can exploit this to present such an inode to the Virtual File System (VFS), triggering a warning in the drop nlink() function when called via ext2 unlink(), ext2 rename(), or ext2 rmdir().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu