CVE-2025-68771
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/01/2026
Last modified:
19/01/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ocfs2: fix kernel BUG in ocfs2_find_victim_chain<br />
<br />
syzbot reported a kernel BUG in ocfs2_find_victim_chain() because the<br />
`cl_next_free_rec` field of the allocation chain list (next free slot in<br />
the chain list) is 0, triggring the BUG_ON(!cl->cl_next_free_rec)<br />
condition in ocfs2_find_victim_chain() and panicking the kernel.<br />
<br />
To fix this, an if condition is introduced in ocfs2_claim_suballoc_bits(),<br />
just before calling ocfs2_find_victim_chain(), the code block in it being<br />
executed when either of the following conditions is true:<br />
<br />
1. `cl_next_free_rec` is equal to 0, indicating that there are no free<br />
chains in the allocation chain list<br />
2. `cl_next_free_rec` is greater than `cl_count` (the total number of<br />
chains in the allocation chain list)<br />
<br />
Either of them being true is indicative of the fact that there are no<br />
chains left for usage.<br />
<br />
This is addressed using ocfs2_error(), which prints<br />
the error log for debugging purposes, rather than panicking the kernel.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/039bef30e320827bac8990c9f29d2a68cd8adb5f
- https://git.kernel.org/stable/c/1f77e5cd563e6387fdf3bb714fcda36cd88ac5e7
- https://git.kernel.org/stable/c/7acc0390e0dd7474c4451d05465a677d55ad4268
- https://git.kernel.org/stable/c/96f1b074c98c20f55a3b23d2ab44d9fb0f619869
- https://git.kernel.org/stable/c/b08a33d5f80efe6979a6e8f905c1a898910c21dd
- https://git.kernel.org/stable/c/d0fd1f732ea8063cecd07a3879b7d815c7ee71ed
- https://git.kernel.org/stable/c/e24aedae71652d4119049f1fbef6532ccbe3966d



