{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72160","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.909Z","datePublished":"2026-08-15T05:53:28.943Z","dateUpdated":"2026-08-17T05:41:03.822Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:41:03.822Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: reject dinodes with non-canonical i_mode type\n\nPatch series \"ocfs2: harden inode validators against forged metadata\", v2.\n\nThis series adds three structural checks to OCFS2 dinode validation so\nmalformed on-disk fields are rejected before ocfs2_populate_inode() copies\nthem into the in-core inode.\n\nThe checks cover:\n\n  - i_mode values whose type bits do not name a canonical POSIX file\n    type;\n  - non-device dinodes whose id1.dev1.i_rdev field is non-zero; and\n  - non-inline dinodes that claim non-zero i_size while i_clusters is\n    zero, covering directories unconditionally and regular files on\n    non-sparse volumes.\n\nThe normal read path reports these through ocfs2_error(), matching the\nexisting suballoc-slot, inline-data, chain-list, and refcount checks.  The\nonline filecheck path uses the same structural predicates but keeps its\nown reporting contract, returning OCFS2_FILECHECK_ERR_INVALIDINO instead\nof calling ocfs2_error().\n\n\nThis patch (of 3):\n\nocfs2_validate_inode_block() currently accepts any non-zero i_mode value. \nocfs2_populate_inode() then copies that mode verbatim into inode->i_mode\nand dispatches on i_mode & S_IFMT to the file/dir/symlink/special_file\niops; an unrecognised type falls through to ocfs2_special_file_iops and\ninit_special_inode().\n\nReject dinodes whose type bits do not name one of the seven canonical\nPOSIX file types.  Use fs_umode_to_ftype(), the same generic file-type\nconversion helper OCFS2 already uses for directory entries, so the\naccepted inode type set matches the kernel file-type vocabulary instead of\nopen-coding a local switch.\n\nApply the same structural check to the online filecheck read path. \nfilecheck keeps its own error namespace, so it reports malformed i_mode\nthrough the filecheck logger and OCFS2_FILECHECK_ERR_INVALIDINO instead of\ncalling ocfs2_error(), but it must not allow a malformed dinode to proceed\ninto ocfs2_populate_inode()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - OCFS2 registers export_operations, so when kernel nfsd serves an OCFS2-backed NFS export on shared cluster storage, remote NFS LOOKUP/GETFH requests drive ocfs2_iget()->ocfs2_read_inode_block()->ocfs2_validate_inode_block() over the network without local syscalls on the server.\nAC:L - An attacker can deterministically set a non-canonical i_mode (e.g., permission bits without S_IFMT) in a crafted OCFS2 dinode and trigger ocfs2_populate_inode() through a normal pathname lookup or NFS file handle resolution; no races or uncontrollable heap layout are required.\nPR:L - Triggering the read path requires only authenticated NFS client access to an exported path containing the forged dinode, or mounting a crafted OCFS2 loop image where CAP_SYS_ADMIN is obtainable by an unprivileged user via user namespaces, matching comparable OCFS2 metadata CVEs.\nUI:N - No victim interaction is needed once forged dinode metadata exists on the volume: a remote NFS client or the attacker mounting a crafted local image can perform the triggering lookup themselves without any third party opening files or mounting the filesystem.\nS:U - Type confusion corrupts in-core inode dispatch state (i_mode/i_rdev/i_op/i_fop mismatch) on the host processing forged OCFS2 metadata; this does not cross VM, container, or IOMMU boundaries into another security authority.\nC:H - Non-canonical i_mode passes validation and populates the inode with attacker-controlled i_rdev before falling through to init_special_inode(), creating type-confused in-core metadata that can expose kernel memory through subsequent VFS getattr and page-cache operations.\nI:H - Accepting forged i_mode installs ocfs2_special_file_iops and attacker-controlled i_rdev on an inode whose type bits are not a valid POSIX special file, leaving inconsistent i_op/i_fop/a_ops state constituting exploitable type confusion writable through further VFS operations.\nA:H - The confused inode state can provoke kernel oops or panics when subsequent VFS operations (e.g., open with missing i_fop, or page-cache I/O via mismatched ocfs2_aops) are attempted on the malformed inode, denying availability until reboot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/inode.c"],"versions":[{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"2e3aac33988ef4e4170141db8e995693ea38357c","status":"affected","versionType":"git"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"fb024ea29f6cb1f01745e5f2e31646f3acb9aa6f","status":"affected","versionType":"git"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"157d31ef45038d89cd19620105e082d43c8e41e0","status":"affected","versionType":"git"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"a5b555bcabbb0aff8745ad181768eaf9d964c1ee","status":"affected","versionType":"git"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"82afe13558354390d8a592a5334d5f4fd72c0e5c","status":"affected","versionType":"git"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"4db3b6a2a8ecf2a89d26a4090ace4072c6fad050","status":"affected","versionType":"git"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"b858f2d57cfc9d57ce61b86051d603dc0ebccd40","status":"affected","versionType":"git"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"5366a017099c6a3c443be908a05f26fd72af12a1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/inode.c"],"versions":[{"version":"2.6.29","status":"affected"},{"version":"0","lessThan":"2.6.29","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.29","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.29","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.29","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.29","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.29","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.29","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.29","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.29","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2e3aac33988ef4e4170141db8e995693ea38357c"},{"url":"https://git.kernel.org/stable/c/fb024ea29f6cb1f01745e5f2e31646f3acb9aa6f"},{"url":"https://git.kernel.org/stable/c/157d31ef45038d89cd19620105e082d43c8e41e0"},{"url":"https://git.kernel.org/stable/c/a5b555bcabbb0aff8745ad181768eaf9d964c1ee"},{"url":"https://git.kernel.org/stable/c/82afe13558354390d8a592a5334d5f4fd72c0e5c"},{"url":"https://git.kernel.org/stable/c/4db3b6a2a8ecf2a89d26a4090ace4072c6fad050"},{"url":"https://git.kernel.org/stable/c/b858f2d57cfc9d57ce61b86051d603dc0ebccd40"},{"url":"https://git.kernel.org/stable/c/5366a017099c6a3c443be908a05f26fd72af12a1"}],"title":"ocfs2: reject dinodes with non-canonical i_mode type","x_generator":{"engine":"bippy-1.2.0"}}}}