← All Advisories

CVE-2026-97926

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97926

Key Details

CVECVE-2026-97926
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ufs: validate cylinder group metadata before caching it

ufs_read_cylinder() copies the cylinder group index and the rotor

positions straight from the on-disk group and caches them without any

check:

ucpi->c_cgx = fs32_to_cpu(sb, ucg->cg_cgx);

ucpi->c_rotor = fs32_to_cpu(sb, ucg->cg_rotor);

ucpi->c_frotor = fs32_to_cpu(sb, ucg->cg_frotor);

ucpi->c_irotor = fs32_to_cpu(sb, ucg->cg_irotor);

They are then used as indices during allocation and free:

- c_cgx indexes the cylinder summary array as

UFS_SB(sb)->fs_cs(ucpi->c_cgx), so a value past s_ncg writes a 32

bit count outside the s_csp allocation.

- c_frotor becomes a bitmap scan start, start = c_frotor >> 3, and

then length = ((s_fpg + 7) >> 3) - start. A start beyond the block

bitmap wraps the unsigned length to a huge value, so ubh_scanc()

walks far past the cylinder group buffers. c_irotor drives the

inode bitmap the same way.

A crafted image can set any of these freely, turning an ordinary

allocation into an out of bounds access.

Reject a cylinder group whose recorded index does not match the group

being read, or whose rotors fall outside the group, before the metadata

is cached. Valid filesystems keep cg_cgx equal to the group number and

the rotors within the group, so only malformed images are rejected. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97926
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97926