PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43076 Linux CVE debrief

CVE-2026-43076 is a Linux kernel OCFS2 inode-validation bug. When the kernel reads an inode from disk, ocfs2_validate_inode_block() did not verify that inline data i_size stayed within the actual inline data capacity (id_count). On a corrupted filesystem, that mismatch can let directory iteration walk past the inline buffer and reach freed memory, resulting in a use-after-free in the directory-entry validation path.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-06
Original CVE updated
2026-06-01
Advisory published
2026-05-06
Advisory updated
2026-06-01

Who should care

Linux kernel maintainers, distro security teams, storage and filesystem administrators, and anyone running systems that may mount or inspect OCFS2 filesystems should care. The issue is in kernel-side filesystem parsing, so exposure depends on whether a system processes a corrupted or malicious OCFS2 filesystem image.

Technical summary

According to the NVD record and linked kernel patch references, the flaw is in OCFS2 inode validation during disk read. The missing check allowed an inode's i_size to exceed inline data capacity (id_count). That invalid state could then propagate into ocfs2_dir_foreach_blk_id(), which may iterate beyond the inline data buffer. The reported failure mode was a garbage rec_len advancing ctx->pos out of bounds and triggering a use-after-free in ocfs2_check_dir_entry(). The fix is to reject inline-data inodes whose i_size is larger than id_count during ocfs2_validate_inode_block().

Defensive priority

High. The CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating substantial impact once a vulnerable system processes a problematic filesystem object, but with local/user-interaction constraints. Patch and reboot or otherwise deploy the fixed kernel builds as soon as practical on systems that use OCFS2.

Recommended defensive actions

  • Apply the vendor kernel updates or stable patches linked in the NVD record for affected branches.
  • Prioritize systems that mount, repair, scan, or otherwise process OCFS2 filesystems.
  • If OCFS2 is not needed on a fleet, consider disabling the module or reducing exposure to untrusted OCFS2 images.
  • Track distro security advisories for backported fixes corresponding to the referenced upstream stable commits.
  • Validate that fixed kernels are deployed across all supported release branches listed by NVD before decommissioning any compensating controls.

Evidence notes

NVD lists CVE-2026-43076 as analyzed, with a Linux kernel CPE and CWE-416. The NVD description states that ocfs2_validate_inode_block() lacked validation of inline-data i_size versus id_count, and that the fix adds a check to reject invalid inodes during inode read. NVD also links multiple kernel.org stable patch references, which support remediation guidance. Affected-version ranges in the NVD record are the authoritative version bounds used here.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43076 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43076

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43076 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43076

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1524af3685b35feac76662cc551cbc37bd14775f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/37f074e65f24f10f8d8df224a572e4cb9e6faf63

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/77d0295725109d77f5854ef5b58c0d06c08168cc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c1de19e891be3bfb3e1d0c7cf07bbb8fb3b77c1b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cd2d765aa7157f852999842af32148128c735d39

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.