Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-74350

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate fast symlink target during inode read ocfs2_validate_inode_block() already rejects several inconsistent self-conta...
Back to all
CVE

DEBIAN-CVE-2026-74350

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate fast symlink target during inode read ocfs2_validate_inode_block() already rejects several inconsistent self-conta...

In the Linux kernel, the following vulnerability has been resolved:  ocfs2: validate fast symlink target during inode read  ocfs2validateinodeblock() already rejects several inconsistent self-contained dinodes before they are exposed to the rest of the filesystem.  Fast symlinks need the same treatment.  A zero-cluster symlink is treated as a fast symlink and later read through pagegetlink() and ocfs2fastsymlinkreadfolio().  That path uses strnlen() on the inline payload and then copies len + 1 bytes into the folio.  If a corrupt dinode stores an isize that does not fit the inline area or omits the terminating NUL at isize, that copy reads past the end of the inode block buffer.  Reject zero-cluster symlink dinodes whose isize exceeds the inline fast-symlink capacity or whose inline payload is not NUL-terminated exactly at isize when the inode block is validated.  This keeps malformed fast symlinks from reaching the read path.  Validation reproduced this kernel report: KASAN use-after-free in ocfs2fastsymlinkreadfolio+0x12c/0x1f0 RIP: 0033:0x7f5c6d859aa7 Read of size 3905 Call trace:   dumpstacklvl+0x66/0xa0 (?:?)   printreport+0xce/0x630 (?:?)   ocfs2fastsymlinkreadfolio+0x12c/0x1f0 (fs/ocfs2/inode.c:?)   srsoaliasreturnthunk+0x5/0xfbef5 (?:?)   virtaddrvalid+0x19f/0x330 (?:?)   kasanreport+0xe0/0x110 (?:?)   kasancheckrange+0x105/0x1b0 (?:?)   asanmemcpy+0x23/0x60 (?:?)   filemapreadfolio+0x27/0xe0 (?:?)   filemapreadfolio+0x35/0xe0 (?:?)   doreadcachefolio+0x138/0x230 (?:?)   pagegetlink+0x26/0x110 (?:?)   pagegetlink+0x2e/0x70 (?:?)   vfsreadlink+0x15e/0x250 (?:?)   touchatime+0x4d/0x370 (?:?)   doreadlinkat+0x186/0x200 (?:?)   douseraddrfault+0x65a/0x890 (?:?)   _x64sysreadlink+0x46/0x60 (?:?)   dosyscall64+0x115/0x6a0 (arch/x86/entry/syscall64.c:87)   entrySYSCALL64afterhwframe+0x77/0x7f (?:?)

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-74350

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
7.1.5-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading