From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 823083FA5CE for ; Fri, 4 Sep 2026 15:18:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535104; cv=none; b=JbLWVoNjfjk4f5DkC5/VCMZC7m9I4eWf1R5M2eoBDZbLeuRj1Htf2dK6+Gnes1PtDrHZCUIhWi7ywS0W9cLp4Rnj4cH4p1+WvNa7yDkDjcRYeiahdS3yGGN1vqjBqpko3EaFcvIkXuDoMCKDzrAW08YBcSLZN+q6ndHHF8F7M/s= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535104; c=relaxed/simple; bh=ETZbPY3Q8QaF4OekUG75Iu8CeNAAYuGSJb1gPikZFXk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=TN/BDRTK+eJ8OSqM/uniZVT0tmxlK2Zg8POzRTxJV2RbXpO9hpBGlP9kBpGzDBhXfRn4a4ySGaRwKBvNwROq0KqkHmbCXqZ9o41N4aB4hGwP0z89ejikU4beVijNqRFaEEBCFNTeyIJT7Vrbp3KrCXHiszn6ouqN4sedjAv3Fwo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=txfnfoSs; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="txfnfoSs" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 25DED1F00A3D; Fri, 4 Sep 2026 15:18:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788535103; bh=qqd/J9tSJLPZH3f2US8R7JwB1tUkR8X50gLk/6WKayo=; h=From:To:Cc:Subject:Date:Reply-To; b=txfnfoSs6lnAnB8XLX3RSAlIiDjiBqFp3UEeQoO/PLr91yYFaeTTljt6hMaBnP33Y dS5nQ/6aspmZyf4w87Iiag1YWTfPmJac9TLuhfcJKsYcxmMIy3XiJGltp0M7Z3PQQe IRNv9fWLVrpYlVaSjMGkBDbxqaaDyMML56oZwrmI= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80809: ocfs2: fix missing metadata reservation for large xattrs Date: Fri, 4 Sep 2026 17:11:48 +0200 Message-ID: <2026090411-CVE-2026-80809-1a7b@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4710; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=E6MCv+iqbKT7a8CwChIiYdU5zHwfWWal58ezbs0z75g=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7vdPOdJrfSEl+q//lj9f6/SNoxV3s4lrFMt2Coscn Gh7Q5izI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACbygZVhwVHvsq/xjJJNuzyS TqeLTq35FfQ6hGGezbrMlKD529ZknxTe25U3a1VGrks2AA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix missing metadata reservation for large xattrs [BUG] lsetxattr() panics the kernel when setting a large xattr value on a fragmented filesystem where the file already has an external xattr block. [CAUSE] ocfs2_calc_xattr_set_need() never reserves metadata blocks for a new xattr value's extent tree when the file already has an external xattr block. The not_found path leaves meta_add at zero, so meta_ac is NULL when ocfs2_xattr_extend_allocation() runs. A new value root has room for a single extent record. On a fragmented filesystem, the allocator cannot satisfy the xattr value in one contiguous run, so each non-contiguous run requires its own extent record. When the value root's extent list is full and meta_ac is NULL, ocfs2_add_clusters_in_btree() returns RESTART_META, and ocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META). [FIX] The case where no xattr block exists yet already calls ocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree metadata. Add the same reservation to the case where an xattr block already exists, making the two cases consistent. Replace the BUG_ON with a -ENOSPC return so that if RESTART_META is returned despite the reservation, the error propagates to userspace instead of panicking the kernel. The Linux kernel CVE team has assigned CVE-2026-80809 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 5.10.267 with commit 743ac908282ac97ef6e73ac3a92df2cc8ecb7479 Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 5.15.218 with commit 04ba24bce61c917b5b3009f0db470cbb72e26a0d Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 6.1.185 with commit b4663405ae29d36011cd712d243456f3f9ab700d Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 6.6.154 with commit 6a009f1e61b11d9e23d3c5aa1dacfb010945da45 Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 6.12.106 with commit b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 6.18.47 with commit 6176313622e34fa3e2b66b9d0682d1e1c6b365c5 Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 7.1.11 with commit a3ccb57086dd7652d5ecb826486144198a98a8e9 Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 7.2.1 with commit 50f0cbec45b0f3fd7e1263d01916518dbf31eb3f Issue introduced in 2.6.35 with commit a78f9f4668949a6588b8872f162e86685c63d023 and fixed in 7.3-rc1 with commit 0cdc7dde00ec63ac714271fa8b2918d630b8da1a Issue introduced in 2.6.34.2 with commit 92f61d8a31e270f9391e7bcc0ac638bd4262a8e0 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80809 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/ocfs2/xattr.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/743ac908282ac97ef6e73ac3a92df2cc8ecb7479 https://git.kernel.org/stable/c/04ba24bce61c917b5b3009f0db470cbb72e26a0d https://git.kernel.org/stable/c/b4663405ae29d36011cd712d243456f3f9ab700d https://git.kernel.org/stable/c/6a009f1e61b11d9e23d3c5aa1dacfb010945da45 https://git.kernel.org/stable/c/b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec https://git.kernel.org/stable/c/6176313622e34fa3e2b66b9d0682d1e1c6b365c5 https://git.kernel.org/stable/c/a3ccb57086dd7652d5ecb826486144198a98a8e9 https://git.kernel.org/stable/c/50f0cbec45b0f3fd7e1263d01916518dbf31eb3f https://git.kernel.org/stable/c/0cdc7dde00ec63ac714271fa8b2918d630b8da1a