7.8
HIGH CVSS 3.1
CVE-2026-72164
ocfs2: avoid moving extents to occupied clusters
Description

In the Linux kernel, the following vulnerability has been resolved: ocfs2: avoid moving extents to occupied clusters For non-auto OCFS2_IOC_MOVE_EXT operations, userspace supplies a physical me_goal. ocfs2_move_extent() initializes new_phys_cpos from that goal and expects ocfs2_probe_alloc_group() to replace it with a free run in the target block group. The probe currently leaves *phys_cpos unchanged if the scan reaches the end of the group without finding a free run. An occupied goal at the last bit can therefore survive the probe and be passed to __ocfs2_move_extent(), which copies file data into a cluster still owned by another inode before the bitmap is updated. When the probe does find a free run, it also subtracts move_len from the ending bit. The start of an N-bit run ending at i is i - N + 1, so the current calculation can report the bit immediately before the free run. Clear *phys_cpos before scanning and use the correct free-run start. Callers already treat a zero result as -ENOSPC, so failed probes no longer continue with an occupied caller-controlled goal.

INFO

Published Date :

Aug. 15, 2026, 6:21 a.m.

Last Modified :

Aug. 17, 2026, 6:18 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-72164 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Update the Linux kernel to resolve an issue with file extent operations.
  • Apply the patch for the ocfs2 module.
  • Update to a corrected Linux kernel version.
  • Ensure file system integrity after the update.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-72164 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-72164 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-72164 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-72164 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '3112afebf2a76e522fbaabcbb0c47aafbdc35932', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '35486b291b8fbde6c4d0b1c79e565c6260d3329d', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '19f7b04924b20b81dabbeed19d5542792ba5b6d6', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': 'e281d892ce5870a50fdc718cb3bfc3dd5b62c728', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': 'd5d5a21fb33cd9b963aea99da81e4dacd452cd95', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '4d1953d3aeb4a7f6623083e1839068ee1c157db2', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '22920541c35a9f23f219038ba5874c843a7c4419', 'versionType': 'git'}], 'programFiles': ['fs/ocfs2/move_extents.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.0'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.0', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/ocfs2/move_extents.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '3112afebf2a76e522fbaabcbb0c47aafbdc35932', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '35486b291b8fbde6c4d0b1c79e565c6260d3329d', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '19f7b04924b20b81dabbeed19d5542792ba5b6d6', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': 'e281d892ce5870a50fdc718cb3bfc3dd5b62c728', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': 'd5d5a21fb33cd9b963aea99da81e4dacd452cd95', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '4d1953d3aeb4a7f6623083e1839068ee1c157db2', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '22920541c35a9f23f219038ba5874c843a7c4419', 'versionType': 'git'}], 'programFiles': ['fs/ocfs2/move_extents.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.0'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.0', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/ocfs2/move_extents.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '3112afebf2a76e522fbaabcbb0c47aafbdc35932', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '35486b291b8fbde6c4d0b1c79e565c6260d3329d', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '19f7b04924b20b81dabbeed19d5542792ba5b6d6', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': 'e281d892ce5870a50fdc718cb3bfc3dd5b62c728', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': 'd5d5a21fb33cd9b963aea99da81e4dacd452cd95', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '4d1953d3aeb4a7f6623083e1839068ee1c157db2', 'versionType': 'git'}, {'status': 'affected', 'version': 'e6b5859cccfa0fec02f3c5b1069481efc7186f47', 'lessThan': '22920541c35a9f23f219038ba5874c843a7c4419', 'versionType': 'git'}], 'programFiles': ['fs/ocfs2/move_extents.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.0'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.0', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/ocfs2/move_extents.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: ocfs2: avoid moving extents to occupied clusters For non-auto OCFS2_IOC_MOVE_EXT operations, userspace supplies a physical me_goal. ocfs2_move_extent() initializes new_phys_cpos from that goal and expects ocfs2_probe_alloc_group() to replace it with a free run in the target block group. The probe currently leaves *phys_cpos unchanged if the scan reaches the end of the group without finding a free run. An occupied goal at the last bit can therefore survive the probe and be passed to __ocfs2_move_extent(), which copies file data into a cluster still owned by another inode before the bitmap is updated. When the probe does find a free run, it also subtracts move_len from the ending bit. The start of an N-bit run ending at i is i - N + 1, so the current calculation can report the bit immediately before the free run. Clear *phys_cpos before scanning and use the correct free-run start. Callers already treat a zero result as -ENOSPC, so failed probes no longer continue with an occupied caller-controlled goal.
    Added Reference https://git.kernel.org/stable/c/0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e
    Added Reference https://git.kernel.org/stable/c/19f7b04924b20b81dabbeed19d5542792ba5b6d6
    Added Reference https://git.kernel.org/stable/c/22920541c35a9f23f219038ba5874c843a7c4419
    Added Reference https://git.kernel.org/stable/c/3112afebf2a76e522fbaabcbb0c47aafbdc35932
    Added Reference https://git.kernel.org/stable/c/35486b291b8fbde6c4d0b1c79e565c6260d3329d
    Added Reference https://git.kernel.org/stable/c/4d1953d3aeb4a7f6623083e1839068ee1c157db2
    Added Reference https://git.kernel.org/stable/c/d5d5a21fb33cd9b963aea99da81e4dacd452cd95
    Added Reference https://git.kernel.org/stable/c/e281d892ce5870a50fdc718cb3bfc3dd5b62c728
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.