PT-2026-34948 · Linux · Linux Kernel

Published

2026-04-24

·

Updated

2026-05-06

·

CVE-2026-31596

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the OCFS2 file system where the ocfs2 group extend() function assumes that the global bitmap inode block returned from ocfs2 inode lock() is already validated. In crafted filesystems, the JBD2-managed buffer path can bypass structural validation and return an invalid dinode to the resize ioctl, leading to a kernel crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-31596
ECHO-586E-C143-D1AA
OPENSUSE-SU-2026:10703-1

Affected Products

Linux Kernel