CVE-2026-53040

Description

A flaw was found in the Oracle Cluster File System Release 2 (OCFS2) in the Linux kernel. A local attacker with the ability to craft a malicious OCFS2 filesystem could trigger a use-after-free vulnerability. This occurs when the OCFS2_IOC_INFO ioctl is issued with the OCFS2_INFO_FL_NON_COHERENT flag, leading to an out-of-bounds bitmap walk. This flaw could result in a denial of service, causing system instability or crashes.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.