← Back to CVE List
Vulnerability Intelligence Report
fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START

CVE-2026-53130

In the Linux kernel, the following vulnerability has been resolved: fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START omfs_fill_super() rejects oversized s_sys_blocksize values (> PAGE_SIZE), but it does not reject values smaller than OMFS_DIR_START (0x1b8 = 440). Later, omfs_make_empty() uses sbi->s_sys_blocksize - OMFS_DIR_START as the length argument to memset(). Since s_sys_blocksize is u32, a crafted filesystem image with s_sys_blocksize < OMFS_DIR_START causes an unsigned underflow there, wrapping to a value near 2^32. That drives a ~4 GiB memset() from bh->b_data + OMFS_DIR_START and overwrites kernel memory far beyond the backing block buffer. Add the corresponding lower-bound check alongside the existing upper-bound check in omfs_fill_super(), so that malformed images are rejected during superblock validation before any filesystem data is processed.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.13%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
Linux Linux a3ab7155ea21aadc8a4d5687e91b3d876973185e < fbc72f5c645155dc2ed3573243ed20f9913e3a54 (affected), a3ab7155ea21aadc8a4d5687e91b3d876973185e < 5822a05a841a10794ad818620dd2af490b0705d3 (affected), a3ab7155ea21aadc8a4d5687e91b3d876973185e < 754ff1bea3819a90c6f33cccfc1a299ef7609f07 (affected), a3ab7155ea21aadc8a4d5687e91b3d876973185e < 131ea3e57fc22936ed0e2c8330f2e36106172f51 (affected), a3ab7155ea21aadc8a4d5687e91b3d876973185e < 79f84af38c9fef9deb0e02c79eb969b5541c2644 (affected), a3ab7155ea21aadc8a4d5687e91b3d876973185e < 6561afc38398e3518a29c5eebb975c30468f98a6 (affected), a3ab7155ea21aadc8a4d5687e91b3d876973185e < 817f16ed62bc58a168417bfb5e859c2a370bab03 (affected), a3ab7155ea21aadc8a4d5687e91b3d876973185e < 0621c385fda1376e967f37ccd534c26c3e511d14 (affected)
Linux Linux 2.6.27 (affected), 0 < 2.6.27 (unaffected), 5.10.258 <= 5.10.* (unaffected), 5.15.209 <= 5.15.* (unaffected), 6.1.175 <= 6.1.* (unaffected), 6.6.141 <= 6.6.* (unaffected), 6.12.91 <= 6.12.* (unaffected), 6.18.33 <= 6.18.* (unaffected), 7.0.10 <= 7.0.* (unaffected), 7.1 <= * (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.129%

Identity & Timeline

StatusPUBLISHED
Assigning Authoritykernel.org · Vendor · USA
Reserved2026-06-09T07:44:35
Published2026-06-24T16:30:57
Last Updated2026-08-05T12:33:24

LINK COPIED TO CLIPBOARD