CVE-2026-53040
Description
A flaw was found in the Oracle Cluster File System Release 2 (OCFS2) in the Linux kernel. A local attacker with the ability to craft a malicious OCFS2 filesystem could trigger a use-after-free vulnerability. This occurs when the OCFS2_IOC_INFO ioctl is issued with the OCFS2_INFO_FL_NON_COHERENT flag, leading to an out-of-bounds bitmap walk. This flaw could result in a denial of service, causing system instability or crashes.
Understanding the Weakness (CWE)
Other
Technical Impact: Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.