In the Linux kernel, the following vulnerability has been resolved: ufs: validate cylinder group...
zetlyn/cve-ghsa vulnerability ghsa GHSA-35q6-8fhf-pg65 cve CVE-2026-97926 known 2026-09-25
https://github.com/advisories/GHSA-35q6-8fhf-pg65
Properties
| cvss | 7receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-97926",
"cvss": {
"score": 7.0,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.0,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [],
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nufs: validate cylinder group metadata before caching it\n\nufs_read_cylinder() copies the cylinder group index and the rotor\npositions straight from the on-disk group and caches them without any\ncheck:\n\n\tucpi->c_cgx = fs32_to_cpu(sb, ucg->cg_cgx);\n\tucpi->c_rotor = fs32_to_cpu(sb, ucg->cg_rotor);\n\tucpi->c_frotor = fs32_to_cpu(sb, ucg->cg_frotor);\n\tucpi->c_irotor = fs32_to_cpu(sb, ucg->cg_irotor);\n\nThey are then used as indices during allocation and free:\n\n - c_cgx indexes the cylinder summary array as\n UFS_SB(sb)->fs_cs(ucpi->c_cgx), so a value past s_ncg writes a 32\n bit count outside the s_csp allocation.\n\n - c_frotor becomes a bitmap scan start, start = c_frotor >> 3, and\n then length = ((s_fpg + 7) >> 3) - start. A start beyond the block\n bitmap wraps the unsigned length to a huge value, so ubh_scanc()\n walks far past the cylinder group buffers. c_irotor drives the\n inode bitmap the same way.\n\nA crafted image can set any of these freely, turning an ordinary\nallocation into an out of bounds access.\n\nReject a cylinder group whose recorded index does not match the group\nbeing read, or whose rotors fall outside the group, before the metadata\nis cached. Valid filesystems keep cg_cgx equal to the group number and\nthe rotors within the group, so only malformed images are rejected.",
"epss": {
"percentage": 0.00154,
"percentile": 0.03802
},
"ghsa_id": "GHSA-35q6-8fhf-pg65",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-35q6-8fhf-pg65",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-35q6-8fhf-pg65"
},
{
"type": "CVE",
"value": "CVE-2026-97926"
}
],
"nvd_published_at": "2026-09-25T11:17:19Z",
"published_at": "2026-09-25T12:31:28Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-97926",
"https://git.kernel.org/stable/c/5902a95066883cf96fa15b2680694fc5dd0c7d11",
"https://git.kernel.org/stable/c/87b12dc360a002eb2d498aa4f01e84347019612d",
"https://git.kernel.org/stable/c/abde9eb33106850dfa367ad3965d3588bb8558d5",
"https://git.kernel.org/stable/c/c9d263be26806d388129fab8c6904bed197fc6af",
"https://github.com/advisories/GHSA-35q6-8fhf-pg65"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nufs: validate cylinder group...",
"type": "unreviewed",
"updated_at": "2026-09-25T15:31:44Z",
"url": "https://api.github.com/advisories/GHSA-35q6-8fhf-pg65",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| severity | high From 7.0 to 8.9. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-97926",
"cvss": {
"score": 7.0,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.0,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [],
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nufs: validate cylinder group metadata before caching it\n\nufs_read_cylinder() copies the cylinder group index and the rotor\npositions straight from the on-disk group and caches them without any\ncheck:\n\n\tucpi->c_cgx = fs32_to_cpu(sb, ucg->cg_cgx);\n\tucpi->c_rotor = fs32_to_cpu(sb, ucg->cg_rotor);\n\tucpi->c_frotor = fs32_to_cpu(sb, ucg->cg_frotor);\n\tucpi->c_irotor = fs32_to_cpu(sb, ucg->cg_irotor);\n\nThey are then used as indices during allocation and free:\n\n - c_cgx indexes the cylinder summary array as\n UFS_SB(sb)->fs_cs(ucpi->c_cgx), so a value past s_ncg writes a 32\n bit count outside the s_csp allocation.\n\n - c_frotor becomes a bitmap scan start, start = c_frotor >> 3, and\n then length = ((s_fpg + 7) >> 3) - start. A start beyond the block\n bitmap wraps the unsigned length to a huge value, so ubh_scanc()\n walks far past the cylinder group buffers. c_irotor drives the\n inode bitmap the same way.\n\nA crafted image can set any of these freely, turning an ordinary\nallocation into an out of bounds access.\n\nReject a cylinder group whose recorded index does not match the group\nbeing read, or whose rotors fall outside the group, before the metadata\nis cached. Valid filesystems keep cg_cgx equal to the group number and\nthe rotors within the group, so only malformed images are rejected.",
"epss": {
"percentage": 0.00154,
"percentile": 0.03802
},
"ghsa_id": "GHSA-35q6-8fhf-pg65",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-35q6-8fhf-pg65",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-35q6-8fhf-pg65"
},
{
"type": "CVE",
"value": "CVE-2026-97926"
}
],
"nvd_published_at": "2026-09-25T11:17:19Z",
"published_at": "2026-09-25T12:31:28Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-97926",
"https://git.kernel.org/stable/c/5902a95066883cf96fa15b2680694fc5dd0c7d11",
"https://git.kernel.org/stable/c/87b12dc360a002eb2d498aa4f01e84347019612d",
"https://git.kernel.org/stable/c/abde9eb33106850dfa367ad3965d3588bb8558d5",
"https://git.kernel.org/stable/c/c9d263be26806d388129fab8c6904bed197fc6af",
"https://github.com/advisories/GHSA-35q6-8fhf-pg65"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nufs: validate cylinder group...",
"type": "unreviewed",
"updated_at": "2026-09-25T15:31:44Z",
"url": "https://api.github.com/advisories/GHSA-35q6-8fhf-pg65",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
In the Linux kernel, the following vulnerability has been resolved:
ufs: validate cylinder group...
In the Linux kernel, the following vulnerability has been resolved:
ufs: validate cylinder group metadata before caching it
ufs_read_cylinder() copies the cylinder group index and the rotor
positions straight from the on-disk group and caches them without any
check:
ucpi->c_cgx = fs32_to_cpu(sb, ucg->cg_cgx);
ucpi->c_rotor = fs32_to_cpu(sb, ucg->cg_rotor);
ucpi->c_frotor = fs32_to_cpu(sb, ucg->cg_frotor);
ucpi->c_irotor = fs32_to_cpu(sb, ucg->cg_irotor);
They are then used as indices during allocation and free:
- c_cgx indexes the cylinder summary array as
UFS_SB(sb)->fs_cs(ucpi->c_cgx), so a value past s_ncg writes a 32
bit count outside the s_csp allocation.
- c_frotor becomes a bitmap scan start, start = c_frotor >> 3, and
then length = ((s_fpg + 7) >> 3) - start. A start beyond the block
bitmap wraps the unsigned length to a huge value, so ubh_scanc()
walks far past the cylinder group buffers. c_irotor drives the
inode bitmap the same way.
A crafted image can set any of these freely, turning an ordinary
allocation into an out of bounds access.
Reject a cylinder group whose recorded index does not match the group
being read, or whose rotors fall outside the group, before the metadata
is cached. Valid filesystems keep cg_cgx equal to the group number and
the rotors within the group, so only malformed images are rejected.