PT-2026-98590 · Linux · Linux

CVE-2026-97926

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
ufs: validate cylinder group metadata before caching it
ufs read cylinder() copies the cylinder group index and the rotor positions straight from the on-disk group and caches them without any check:
ucpi->c cgx  = fs32 to cpu(sb, ucg->cg cgx);
ucpi->c rotor = fs32 to cpu(sb, ucg->cg rotor);
ucpi->c frotor = fs32 to cpu(sb, ucg->cg frotor);
ucpi->c irotor = fs32 to cpu(sb, ucg->cg irotor);
They are then used as indices during allocation and free:
  • c cgx indexes the cylinder summary array as UFS SB(sb)->fs cs(ucpi->c cgx), so a value past s ncg writes a 32 bit count outside the s csp allocation.
  • c frotor becomes a bitmap scan start, start = c frotor >> 3, and then length = ((s fpg + 7) >> 3) - start. A start beyond the block bitmap wraps the unsigned length to a huge value, so ubh scanc() walks far past the cylinder group buffers. c irotor drives the inode bitmap the same way.
A crafted image can set any of these freely, turning an ordinary allocation into an out of bounds access.
Reject a cylinder group whose recorded index does not match the group being read, or whose rotors fall outside the group, before the metadata is cached. Valid filesystems keep cg cgx equal to the group number and the rotors within the group, so only malformed images are rejected.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97926

Affected Products

Linux