From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-80809: ocfs2: fix missing metadata reservation for large xattrs
Date: Fri, 4 Sep 2026 17:11:48 +0200 [thread overview]
Message-ID: <2026090411-CVE-2026-80809-1a7b@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: fix missing metadata reservation for large xattrs
[BUG]
lsetxattr() panics the kernel when setting a large xattr value on a
fragmented filesystem where the file already has an external xattr
block.
[CAUSE]
ocfs2_calc_xattr_set_need() never reserves metadata blocks for a new
xattr value's extent tree when the file already has an external xattr
block. The not_found path leaves meta_add at zero, so meta_ac is NULL
when ocfs2_xattr_extend_allocation() runs.
A new value root has room for a single extent record. On a fragmented
filesystem, the allocator cannot satisfy the xattr value in one
contiguous run, so each non-contiguous run requires its own extent
record. When the value root's extent list is full and meta_ac is NULL,
ocfs2_add_clusters_in_btree() returns RESTART_META, and
ocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META).
[FIX]
The case where no xattr block exists yet already calls
ocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree
metadata. Add the same reservation to the case where an xattr block
already exists, making the two cases consistent.
Replace the BUG_ON with a -ENOSPC return so that if RESTART_META is
returned despite the reservation, the error propagates to userspace
instead of panicking the kernel.
The Linux kernel CVE team has assigned CVE-2026-80809 to this issue.
Affected and fixed versions
===========================
Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 5.10.267 with commit 743ac908282ac97ef6e73ac3a92df2cc8ecb7479
Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 5.15.218 with commit 04ba24bce61c917b5b3009f0db470cbb72e26a0d
Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 6.1.185 with commit b4663405ae29d36011cd712d243456f3f9ab700d
Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 6.6.154 with commit 6a009f1e61b11d9e23d3c5aa1dacfb010945da45
Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 6.12.106 with commit b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec
Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 6.18.47 with commit 6176313622e34fa3e2b66b9d0682d1e1c6b365c5
Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 7.1.11 with commit a3ccb57086dd7652d5ecb826486144198a98a8e9
Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 7.2.1 with commit 50f0cbec45b0f3fd7e1263d01916518dbf31eb3f
Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 7.3-rc1 with commit 0cdc7dde00ec63ac714271fa8b2918d630b8da1a
Issue introduced in 2.6.34.2 with commit 92f61d8a31e270f9391e7bcc0ac638bd4262a8e0
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80809
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/ocfs2/xattr.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/743ac908282ac97ef6e73ac3a92df2cc8ecb7479
https://git.kernel.org/stable/c/04ba24bce61c917b5b3009f0db470cbb72e26a0d
https://git.kernel.org/stable/c/b4663405ae29d36011cd712d243456f3f9ab700d
https://git.kernel.org/stable/c/6a009f1e61b11d9e23d3c5aa1dacfb010945da45
https://git.kernel.org/stable/c/b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec
https://git.kernel.org/stable/c/6176313622e34fa3e2b66b9d0682d1e1c6b365c5
https://git.kernel.org/stable/c/a3ccb57086dd7652d5ecb826486144198a98a8e9
https://git.kernel.org/stable/c/50f0cbec45b0f3fd7e1263d01916518dbf31eb3f
https://git.kernel.org/stable/c/0cdc7dde00ec63ac714271fa8b2918d630b8da1a
reply other threads:[~2026-09-04 15:18 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026090411-CVE-2026-80809-1a7b@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.