CVE-2026-80881 (GCVE-0-2026-80881)

Vulnerability from cvelistv5 – Published: 2026-09-04 16:49 – Updated: 2026-09-04 16:49
VLAI
Title
ocfs2: fix buffer head management in ocfs2_read_blocks()
Summary
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix buffer head management in ocfs2_read_blocks() In ocfs2_read_blocks(), caller should't assume that buffer head returned by 'sb_getblk()' is exclusively owned and so 'put_bh()' always drops b_count from 1 to 0. If it is not so, buffer head remains on hold and likely to be returned by the next call to 'sb_getblk()' unchanged - that is, with BH_Uptodate bit set even if it has failed validation previously, thus allowing to insert that buffer head into OCFS2 metadata cache and submit it to upper layers. To avoid such a scenario, BH_Uptodate should be cleared immediately after 'validate()' callback has detected some data inconsistency.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: cf76c78595ca87548ca5e45c862ac9e0949c4687 , < a4eae1499c760949a93459d11390bd1fd823d31d (git)
Affected: cf76c78595ca87548ca5e45c862ac9e0949c4687 , < 4ab17e328522a4df5fe0f0dcf39098118b1feeaa (git)
Affected: cf76c78595ca87548ca5e45c862ac9e0949c4687 , < 5927acb3e2c99985a14adecd9d1b67ba191c622d (git)
Affected: cf76c78595ca87548ca5e45c862ac9e0949c4687 , < ecb3f9386f4353034caef77239473c627232db17 (git)
Affected: cf76c78595ca87548ca5e45c862ac9e0949c4687 , < 61f7a5acb3bf8fc97dad78f54b1e8d0e1c819766 (git)
Affected: cf76c78595ca87548ca5e45c862ac9e0949c4687 , < 0e389fc290c350c67591abf4c367119f4689f310 (git)
Affected: cf76c78595ca87548ca5e45c862ac9e0949c4687 , < 9e7a057934cdd58e4cc94350bcfe5367bbee0f8e (git)
Affected: cf76c78595ca87548ca5e45c862ac9e0949c4687 , < 6371a07148ee979af22a9d6f4c277462953a9a4a (git)
Affected: 01f93d5e36753fc4d06ec67f05ce78c9c6f2dd56 (git)
Affected: 65cbd1279f4b999d56a838344a30642db24cd215 (git)
Affected: 97e1db17bc1ef4c2e1789bc9323c7be44fba53f8 (git)
Affected: 6c150df9c2e80b5cf86f5a0d98beb7390ad63bfc (git)
Affected: 4.4.204 , < 4.5 (semver)
Affected: 4.9.204 , < 4.10 (semver)
Affected: 4.14.157 , < 4.15 (semver)
Affected: 4.19.87 , < 4.20 (semver)
Create a notification for this product.
Linux Linux Affected: 4.20
Unaffected: 0 , < 4.20 (semver)
Unaffected: 5.10.261 , ≤ 5.10.* (semver)
Unaffected: 5.15.212 , ≤ 5.15.* (semver)
Unaffected: 6.1.178 , ≤ 6.1.* (semver)
Unaffected: 6.6.145 , ≤ 6.6.* (semver)
Unaffected: 6.12.97 , ≤ 6.12.* (semver)
Unaffected: 6.18.40 , ≤ 6.18.* (semver)
Unaffected: 7.1.5 , ≤ 7.1.* (semver)
Unaffected: 7.2 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/ocfs2/buffer_head_io.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "a4eae1499c760949a93459d11390bd1fd823d31d",
              "status": "affected",
              "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
              "versionType": "git"
            },
            {
              "lessThan": "4ab17e328522a4df5fe0f0dcf39098118b1feeaa",
              "status": "affected",
              "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
              "versionType": "git"
            },
            {
              "lessThan": "5927acb3e2c99985a14adecd9d1b67ba191c622d",
              "status": "affected",
              "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
              "versionType": "git"
            },
            {
              "lessThan": "ecb3f9386f4353034caef77239473c627232db17",
              "status": "affected",
              "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
              "versionType": "git"
            },
            {
              "lessThan": "61f7a5acb3bf8fc97dad78f54b1e8d0e1c819766",
              "status": "affected",
              "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
              "versionType": "git"
            },
            {
              "lessThan": "0e389fc290c350c67591abf4c367119f4689f310",
              "status": "affected",
              "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
              "versionType": "git"
            },
            {
              "lessThan": "9e7a057934cdd58e4cc94350bcfe5367bbee0f8e",
              "status": "affected",
              "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
              "versionType": "git"
            },
            {
              "lessThan": "6371a07148ee979af22a9d6f4c277462953a9a4a",
              "status": "affected",
              "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01f93d5e36753fc4d06ec67f05ce78c9c6f2dd56",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "65cbd1279f4b999d56a838344a30642db24cd215",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "97e1db17bc1ef4c2e1789bc9323c7be44fba53f8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6c150df9c2e80b5cf86f5a0d98beb7390ad63bfc",
              "versionType": "git"
            },
            {
              "lessThan": "4.5",
              "status": "affected",
              "version": "4.4.204",
              "versionType": "semver"
            },
            {
              "lessThan": "4.10",
              "status": "affected",
              "version": "4.9.204",
              "versionType": "semver"
            },
            {
              "lessThan": "4.15",
              "status": "affected",
              "version": "4.14.157",
              "versionType": "semver"
            },
            {
              "lessThan": "4.20",
              "status": "affected",
              "version": "4.19.87",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/ocfs2/buffer_head_io.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.20"
            },
            {
              "lessThan": "4.20",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.261",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.212",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.178",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.145",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.97",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.40",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.5",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.4.204",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.9.204",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.14.157",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.19.87",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix buffer head management in ocfs2_read_blocks()\n\nIn ocfs2_read_blocks(), caller should\u0027t assume that buffer head returned\nby \u0027sb_getblk()\u0027 is exclusively owned and so \u0027put_bh()\u0027 always drops\nb_count from 1 to 0.  If it is not so, buffer head remains on hold and\nlikely to be returned by the next call to \u0027sb_getblk()\u0027 unchanged - that\nis, with BH_Uptodate bit set even if it has failed validation previously,\nthus allowing to insert that buffer head into OCFS2 metadata cache and\nsubmit it to upper layers.  To avoid such a scenario, BH_Uptodate should\nbe cleared immediately after \u0027validate()\u0027 callback has detected some data\ninconsistency."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-04T16:49:11.758Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a4eae1499c760949a93459d11390bd1fd823d31d"
        },
        {
          "url": "https://git.kernel.org/stable/c/4ab17e328522a4df5fe0f0dcf39098118b1feeaa"
        },
        {
          "url": "https://git.kernel.org/stable/c/5927acb3e2c99985a14adecd9d1b67ba191c622d"
        },
        {
          "url": "https://git.kernel.org/stable/c/ecb3f9386f4353034caef77239473c627232db17"
        },
        {
          "url": "https://git.kernel.org/stable/c/61f7a5acb3bf8fc97dad78f54b1e8d0e1c819766"
        },
        {
          "url": "https://git.kernel.org/stable/c/0e389fc290c350c67591abf4c367119f4689f310"
        },
        {
          "url": "https://git.kernel.org/stable/c/9e7a057934cdd58e4cc94350bcfe5367bbee0f8e"
        },
        {
          "url": "https://git.kernel.org/stable/c/6371a07148ee979af22a9d6f4c277462953a9a4a"
        }
      ],
      "title": "ocfs2: fix buffer head management in ocfs2_read_blocks()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-80881",
    "datePublished": "2026-09-04T16:49:11.758Z",
    "dateReserved": "2026-08-26T14:34:25.799Z",
    "dateUpdated": "2026-09-04T16:49:11.758Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-80881",
      "date": "2026-10-03",
      "epss": "0.0022",
      "percentile": "0.11297"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "fs/ocfs2/buffer_head_io.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "a4eae1499c760949a93459d11390bd1fd823d31d",
                    "status": "affected",
                    "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "4ab17e328522a4df5fe0f0dcf39098118b1feeaa",
                    "status": "affected",
                    "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5927acb3e2c99985a14adecd9d1b67ba191c622d",
                    "status": "affected",
                    "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ecb3f9386f4353034caef77239473c627232db17",
                    "status": "affected",
                    "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "61f7a5acb3bf8fc97dad78f54b1e8d0e1c819766",
                    "status": "affected",
                    "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "0e389fc290c350c67591abf4c367119f4689f310",
                    "status": "affected",
                    "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "9e7a057934cdd58e4cc94350bcfe5367bbee0f8e",
                    "status": "affected",
                    "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "6371a07148ee979af22a9d6f4c277462953a9a4a",
                    "status": "affected",
                    "version": "cf76c78595ca87548ca5e45c862ac9e0949c4687",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "01f93d5e36753fc4d06ec67f05ce78c9c6f2dd56",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "65cbd1279f4b999d56a838344a30642db24cd215",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "97e1db17bc1ef4c2e1789bc9323c7be44fba53f8",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "6c150df9c2e80b5cf86f5a0d98beb7390ad63bfc",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "4.5",
                    "status": "affected",
                    "version": "4.4.204",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "4.10",
                    "status": "affected",
                    "version": "4.9.204",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "4.15",
                    "status": "affected",
                    "version": "4.14.157",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "4.20",
                    "status": "affected",
                    "version": "4.19.87",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "fs/ocfs2/buffer_head_io.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.20"
                  },
                  {
                    "lessThan": "4.20",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10.*",
                    "status": "unaffected",
                    "version": "5.10.261",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15.*",
                    "status": "unaffected",
                    "version": "5.15.212",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.178",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.145",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.97",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.40",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.1.*",
                    "status": "unaffected",
                    "version": "7.1.5",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.2",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix buffer head management in ocfs2_read_blocks()\n\nIn ocfs2_read_blocks(), caller should\u0027t assume that buffer head returned\nby \u0027sb_getblk()\u0027 is exclusively owned and so \u0027put_bh()\u0027 always drops\nb_count from 1 to 0.  If it is not so, buffer head remains on hold and\nlikely to be returned by the next call to \u0027sb_getblk()\u0027 unchanged - that\nis, with BH_Uptodate bit set even if it has failed validation previously,\nthus allowing to insert that buffer head into OCFS2 metadata cache and\nsubmit it to upper layers.  To avoid such a scenario, BH_Uptodate should\nbe cleared immediately after \u0027validate()\u0027 callback has detected some data\ninconsistency."
          }
        ],
        "id": "CVE-2026-80881",
        "lastModified": "2026-09-04T17:17:00.390",
        "metrics": {},
        "published": "2026-09-04T17:17:00.390",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/0e389fc290c350c67591abf4c367119f4689f310"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/4ab17e328522a4df5fe0f0dcf39098118b1feeaa"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/5927acb3e2c99985a14adecd9d1b67ba191c622d"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/61f7a5acb3bf8fc97dad78f54b1e8d0e1c819766"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/6371a07148ee979af22a9d6f4c277462953a9a4a"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/9e7a057934cdd58e4cc94350bcfe5367bbee0f8e"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/a4eae1499c760949a93459d11390bd1fd823d31d"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ecb3f9386f4353034caef77239473c627232db17"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…