CVE-2026-74351
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: rebase copied fsdlm LVB pointers in locking_state
The locking_state debugfs iterator snapshots struct ocfs2_lock_res by value under ocfs2_dlm_tracking_lock and later formats that copy in ocfs2_dlm_seq_show(). That is fine for the inline fields, but the userspace fsdlm stack stores the LVB through lksb_fsdlm.sb_lvbptr. Once the iterator drops the tracking lock, a copied non-NULL sb_lvbptr still points into the original lockres owner, so teardown can free that container before the debugfs dump walks the raw LVB bytes.
Rebase the copied sb_lvbptr to the copied l_lksb before dumping the raw LVB. The seq snapshot already carries the inline LVB storage reserved in struct ocfs2_dlm_lksb, so the debugfs reader can dump the copied bytes without borrowing the original lockres lifetime.
Leer descripción completaMostrar menos
The buggy scenario involves two paths, with each column showing the order within that path:
Detalles técnicos trazas, registros y código del informe original
locking_state reader: lockres teardown:
1. ocfs2_dlm_seq_start()/next() 1. file release or another owner
copies struct ocfs2_lock_res teardown reaches
2. ocfs2_dlm_seq_show() formats ocfs2_lock_res_free()
the copied row 2. the lockres is removed from the
3. ocfs2_dlm_lvb() follows the tracking list
copied sb_lvbptr 3. the owner frees the original
lockres container
Validation reproduced this kernel report:
KASAN slab-use-after-free in ocfs2_dlm_seq_show+0x1bd/0x430
RIP: 0033:0x7f8ec4b1e29d
The buggy address belongs to the object at ffff88810a1e0800 which belongs
to the cache kmalloc-1k of size 1024
The buggy address is located 368 bytes inside of freed 1024-byte region
[ffff88810a1e0800, ffff88810a1e0c00)
Read of size 1
Call trace:
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x630
ocfs2_dlm_seq_show+0x1bd/0x430 (fs/ocfs2/dlmglue.c:3137)
srso_alias_return_thunk+0x5/0xfbef5
__virt_addr_valid+0x19f/0x330
kasan_report+0xe0/0x110
seq_read_iter+0x29d/0x790
seq_read+0x20a/0x280
find_held_lock+0x2b/0x80
rcu_read_unlock+0x18/0x70
full_proxy_read+0x9e/0xd0
vfs_read+0x12c/0x590
ksys_read+0xd2/0x170
do_user_addr_fault+0x65a/0x890
do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Allocated by task stack:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
__kasan_kmalloc+0xaa/0xb0
ocfs2_file_open+0x13e/0x300
do_dentry_open+0x233/0x7f0
vfs_open+0x5a/0x1b0
path_openat+0x66d/0x1540
do_file_open+0x186/0x2b0
do_sys_openat2+0xce/0x150
__x64_sys_openat+0xd0/0x140
do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task stack:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x5f/0x80
kfree+0x313/0x590
ocfs2_file_release+0x138/0x260
__fput+0x1df/0x4b0
fput_close_sync+0xd2/0x170
__x64_sys_close+0x55/0x90
do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
entry_SYSCALL_64_after_hwframe+0x77/0x7fCVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/07aa4a8ebacde3d0ba50f60d2964f274ee7629bc
- https://git.kernel.org/stable/c/185427b5f7a209254c85c18aad5a4a8e009b2f30
- https://git.kernel.org/stable/c/610a0d2a35496738e1472fb0f318d5008a1c634f
- https://git.kernel.org/stable/c/6b38a5b8ee951e5b244e9a3c3d28d0f5e7c51411
- https://git.kernel.org/stable/c/8614a8f7e81edd34c9f67e454e7024fd12a2a341
- https://git.kernel.org/stable/c/93612d48fa42b3d1a637eb9279e15281c611c000
- https://git.kernel.org/stable/c/bb44a7690a4d553da705919cf666a80f5ca9011c
- https://git.kernel.org/stable/c/e037c1250cc90e7aacb002357d1b0399fc65ecfc
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74351",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "cf4d8d75d8aba537a19b313a9364fd08ddbd5622",
"lessThan": "185427b5f7a209254c85c18aad5a4a8e009b2f30",
"versionType": "git"
},
{
"status": "affected",
"version": "cf4d8d75d8aba537a19b313a9364fd08ddbd5622",
"lessThan": "07aa4a8ebacde3d0ba50f60d2964f274ee7629bc",
"versionType": "git"
},
{
"status": "affected",
"version": "cf4d8d75d8aba537a19b313a9364fd08ddbd5622",
"lessThan": "e037c1250cc90e7aacb002357d1b0399fc65ecfc",
"versionType": "git"
},
{
"status": "affected",
"version": "cf4d8d75d8aba537a19b313a9364fd08ddbd5622",
"lessThan": "6b38a5b8ee951e5b244e9a3c3d28d0f5e7c51411",
"versionType": "git"
},
{
"status": "affected",
"version": "cf4d8d75d8aba537a19b313a9364fd08ddbd5622",
"lessThan": "8614a8f7e81edd34c9f67e454e7024fd12a2a341",
"versionType": "git"
},
{
"status": "affected",
"version": "cf4d8d75d8aba537a19b313a9364fd08ddbd5622",
"lessThan": "bb44a7690a4d553da705919cf666a80f5ca9011c",
"versionType": "git"
},
{
"status": "affected",
"version": "cf4d8d75d8aba537a19b313a9364fd08ddbd5622",
"lessThan": "610a0d2a35496738e1472fb0f318d5008a1c634f",
"versionType": "git"
},
{
"status": "affected",
"version": "cf4d8d75d8aba537a19b313a9364fd08ddbd5622",
"lessThan": "93612d48fa42b3d1a637eb9279e15281c611c000",
"versionType": "git"
}
],
"programFiles": [
"fs/ocfs2/dlmglue.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.26"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.26",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/ocfs2/dlmglue.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:36.383",
"references": [
{
"url": "https://git.kernel.org/stable/c/07aa4a8ebacde3d0ba50f60d2964f274ee7629bc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/185427b5f7a209254c85c18aad5a4a8e009b2f30",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/610a0d2a35496738e1472fb0f318d5008a1c634f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6b38a5b8ee951e5b244e9a3c3d28d0f5e7c51411",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8614a8f7e81edd34c9f67e454e7024fd12a2a341",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/93612d48fa42b3d1a637eb9279e15281c611c000",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bb44a7690a4d553da705919cf666a80f5ca9011c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e037c1250cc90e7aacb002357d1b0399fc65ecfc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: rebase copied fsdlm LVB pointers in locking_state\n\nThe locking_state debugfs iterator snapshots struct ocfs2_lock_res by\nvalue under ocfs2_dlm_tracking_lock and later formats that copy in\nocfs2_dlm_seq_show(). That is fine for the inline fields, but the\nuserspace fsdlm stack stores the LVB through lksb_fsdlm.sb_lvbptr. Once\nthe iterator drops the tracking lock, a copied non-NULL sb_lvbptr still\npoints into the original lockres owner, so teardown can free that\ncontainer before the debugfs dump walks the raw LVB bytes.\n\nRebase the copied sb_lvbptr to the copied l_lksb before dumping the raw\nLVB. The seq snapshot already carries the inline LVB storage reserved in\nstruct ocfs2_dlm_lksb, so the debugfs reader can dump the copied bytes\nwithout borrowing the original lockres lifetime.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nlocking_state reader: lockres teardown:\n1. ocfs2_dlm_seq_start()/next() 1. file release or another owner\n copies struct ocfs2_lock_res teardown reaches\n2. ocfs2_dlm_seq_show() formats ocfs2_lock_res_free()\n the copied row 2. the lockres is removed from the\n3. ocfs2_dlm_lvb() follows the tracking list\n copied sb_lvbptr 3. the owner frees the original\n lockres container\n\nValidation reproduced this kernel report:\nKASAN slab-use-after-free in ocfs2_dlm_seq_show+0x1bd/0x430\nRIP: 0033:0x7f8ec4b1e29d\nThe buggy address belongs to the object at ffff88810a1e0800 which belongs\nto the cache kmalloc-1k of size 1024\nThe buggy address is located 368 bytes inside of freed 1024-byte region\n[ffff88810a1e0800, ffff88810a1e0c00)\nRead of size 1\nCall trace:\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n ocfs2_dlm_seq_show+0x1bd/0x430 (fs/ocfs2/dlmglue.c:3137)\n srso_alias_return_thunk+0x5/0xfbef5\n __virt_addr_valid+0x19f/0x330\n kasan_report+0xe0/0x110\n seq_read_iter+0x29d/0x790\n seq_read+0x20a/0x280\n find_held_lock+0x2b/0x80\n rcu_read_unlock+0x18/0x70\n full_proxy_read+0x9e/0xd0\n vfs_read+0x12c/0x590\n ksys_read+0xd2/0x170\n do_user_addr_fault+0x65a/0x890\n do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nAllocated by task stack:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n ocfs2_file_open+0x13e/0x300\n do_dentry_open+0x233/0x7f0\n vfs_open+0x5a/0x1b0\n path_openat+0x66d/0x1540\n do_file_open+0x186/0x2b0\n do_sys_openat2+0xce/0x150\n __x64_sys_openat+0xd0/0x140\n do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nFreed by task stack:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x5f/0x80\n kfree+0x313/0x590\n ocfs2_file_release+0x138/0x260\n __fput+0x1df/0x4b0\n fput_close_sync+0xd2/0x170\n __x64_sys_close+0x55/0x90\n do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n entry_SYSCALL_64_after_hwframe+0x77/0x7f"
}
],
"lastModified": "2026-08-17T06:19:29.780",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}