{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.176-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.85-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.14-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ocfs2: validate inline data i_size during inode read  When reading an inode from disk, ocfs2_validate_inode_block() performs various sanity checks but does not validate the size of inline data.  If the filesystem is corrupted, an inode's i_size can exceed the actual inline data capacity (id_count).  This causes ocfs2_dir_foreach_blk_id() to iterate beyond the inline data buffer, triggering a use-after-free when accessing directory entries from freed memory.  In the syzbot report:   - i_size was 1099511627576 bytes (~1TB)   - Actual inline data capacity (id_count) is typically \u003c256 bytes   - A garbage rec_len (54648) caused ctx-\u003epos to jump out of bounds   - This triggered a UAF in ocfs2_check_dir_entry()  Fix by adding a validation check in ocfs2_validate_inode_block() to ensure inodes with inline data have i_size \u003c= id_count.  This catches the corruption early during inode read and prevents all downstream code from operating on invalid data.",
  "id": "DEBIAN-CVE-2026-43076",
  "modified": "2026-09-14T16:47:32.620121852Z",
  "published": "2026-05-06T10:16:20.590Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-43076"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-43076"
  ]
}