Review reviewHigh

CVE-2026-53040

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate bg_bits during freefrag scan [BUG] A crafted filesystem can trigger an out-of-bounds bitmap walk when OCFS2_IOC_INFO is issued with OCFS2_INFO_FL_NON_COHERENT. BUG: KASAN: use-after-free in instrument_atomic_read include/linux/instrumented.h:68 [inline] BUG: KASAN: use-after-free in _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline] BUG: KASAN: use-after-free in test_bit_le include/asm-generic/bitops/le.h:21 [inline] BUG: KASAN: use-after-free in ocfs2_info_freefrag_scan_chain fs/ocf...

CVSS
7.1
EPSS
0.12%
2.37% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.12%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate bg_bits during freefrag scan [BUG] A crafted filesystem can trigger an out-of-bounds bitmap walk when OCFS2_IOC_INFO is issued with OCFS2_INFO_FL_NON_COHERENT. BUG: KASAN: use-after-free in instrument_atomic_read include/linux/instrumented.h:68 [inline] BUG: KASAN: use-after-free in _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline] BUG: KASAN: use-after-free in test_bit_le include/asm-generic/bitops/le.h:21 [inline] BUG: KASAN: use-after-free in ocfs2_info_freefrag_scan_chain fs/ocf...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= d24a10b9f8ed548981696cd36e2b4f16e6f360b1 < bb2906a1065ec28de021bac2ed03f2624edd7d07, >= d24a10b9f8ed548981696cd36e2b4f16e6f360b1 < 3e167e230d19cd273108bab2e4c61800fc335ae8, >= d24a10b9f8ed548981696cd36e2b4f16e6f360b1 < 0998674eec138c55e9e349b9cbd9dbc5129a9cc8, >= d24a10b9f8ed548981696cd36e2b4f16e6f360b1 < bb3c54d1e71578521111f1a1ee7d5f4761a242b8, >= d24a10b9f8ed548981696cd36e2b4f16e6f360b1 < 05d0cbea41167b6b061c6ba5b70ee5a9a7a24c9e, >= d24a10b9f8ed548981696cd36e2b4f16e6f360b1 < 4c2d62ddde8928db12f4608950b67a20e67deab2, >= d24a10b9f8ed548981696cd36e2b4f16e6f360b1 < e0dcf12665d6dde37facf790803cdad44d5c328c, >= d24a10b9f8ed548981696cd36e2b4f16e6f360b1 < 8f687eeed3da3012152b0f9473f578869de0cd7b, >= 3.0, >= 3.0 < 5.10.258, >= 5.11 < 5.15.209, >= 5.16 < 6.1.175, >= 6.2 < 6.6.141, >= 6.7 < 6.12.91, >= 6.13 < 6.18.33, >= 6.19 < 7.0.10
Fixed versions
5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-416