CVE-2026-43168

MEDIUM EPSS 2.4%
Published May 6, 20261mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 6, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix reflink preserve cleanup issue commit c06c303832ec ("ocfs2: fix xattr array entry __counted_by error") doesn't handle all cases and the cleanup job for preserved xattr entries still has bug: - the 'last' pointer should be shifted by one unit after cleanup an array entry. - current code logic doesn't cleanup the first entry when xh_count is 1. Note, commit c06c303832ec is also a bug fix for 0fe9b66c65f3.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel*≥2.6.32  –  <5.10.252
linuxlinux_kernel*≥5.11  –  <5.15.202
linuxlinux_kernel*≥5.16  –  <6.1.165
linuxlinux_kernel*≥6.2  –  <6.6.128
linuxlinux_kernel*≥6.7  –  <6.12.75
linuxlinux_kernel*≥6.13  –  <6.18.16
linuxlinux_kernel*≥6.19  –  <6.19.6

References 8

  • git.kernel.org https://git.kernel.org/stable/c/02acc9f72365e50eb45a56b7dacb9114ca3b503c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2f4daccd9d9b8b2952df7878df8c2e8ba6439398
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3bdc3766aafb052aef4baadef455a84c1c0a059d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5138c936c2c82c9be8883921854bc6f7e1177d8c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8ff329353134280b203cb2bce95311cb8f7cbd8a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b2952dbeac2c3c527cb0519d5ffaeb95b062466a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bb273b68c1719c2925e05557f7e7099edb066680
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c44d86ca949cb1e5566ad14510cc26fa1a17e2d8
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/02acc9f72365e50eb45a56b7dacb9114ca3b503c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2f4daccd9d9b8b2952df7878df8c2e8ba6439398
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3bdc3766aafb052aef4baadef455a84c1c0a059d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5138c936c2c82c9be8883921854bc6f7e1177d8c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8ff329353134280b203cb2bce95311cb8f7cbd8a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b2952dbeac2c3c527cb0519d5ffaeb95b062466a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bb273b68c1719c2925e05557f7e7099edb066680
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c44d86ca949cb1e5566ad14510cc26fa1a17e2d8
    Patch