In the Linux kernel, the following vulnerability has been resolved:
gfs2: Always check inode size of inline inodes
Check if the inode size of stuffed (inline) inodes is within the allowed
range when reading inodes from disk (gfs2_dinode_in()). This prevents
us from on-disk corruption.
The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just
truncate inline data to the maximum allowed size don't actually make
sense, and they can be removed now as well.
An official patch is available. Apply the patch as soon as possible.
CVSS v4.0 Metrics
Exploitability
Attack VectorLocal
ComplexityLow
RequirementsPresent
PrivilegesLow
User InteractionNone
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusOfficial Patch
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | nvd | AV: P→L, AC: H→L, PR: H→L, UI: A→N, VA: N→H | 0.0 → 1.9 |
| 2026-07-21 | nvd | patch: Unavailable→Official Patch | 0.0 → 0.0 |
| 2026-07-21 | cve.org | initial, patch: Unavailable | 0.0 |
Affected Software
| Vendor | Product | Version |
|---|
| Linux | Linux | ≥ 5.15.93, ≤ 5.15.* |
| Linux | Linux | < 45df749f827c286adbc951f2a4865b67 |
| Linux | Linux | < 4d4cb76636134bf9a0c9c3432dae936f |
| Linux | Linux | < 7c414f6f06e9a3934901b6edc3177ae5 |
| Linux | Linux | < 46c9088cabd4d0469fdb61ac2a9c5003 |
| Linux | Linux | < 2.6.19 |
| Linux | Linux | < d458a0984429c2d47e60254f5bc4119c |
| Linux | Linux | ≥ 6.2, ≤ * |
| Linux | Linux | < 70376c7ff31221f1d21db5611d8209e6 |
| Linux | Linux | ≥ 5.10.177, ≤ 5.10.* |
| Linux | Linux | ≥ 4.19.280, ≤ 4.19.* |
| Linux | Linux | ≥ 5.4.240, ≤ 5.4.* |
| Linux | Linux | ≥ 6.1.11, ≤ 6.1.* |
| Linux | Linux | 2.6.19 |
| linux | linux_kernel | ≥ 5.16, < 6.1.11 |
| linux | linux_kernel | ≥ 5.11, < 5.15.93 |
| linux | linux_kernel | ≥ 5.5, < 5.10.177 |
| linux | linux_kernel | ≥ 4.20, < 5.4.240 |
| linux | linux_kernel | < 4.19.280 |
Published: 2025-03-27