{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ocfs2: don't BUG_ON an invalid journal dinode  [BUG] A fuzzed OCFS2 image can corrupt the current slot journal dinode while mount is still in progress. The mount path first reports the invalid journal block and then crashes in shutdown:  kernel BUG at fs/ocfs2/journal.c:1034! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:ocfs2_journal_toggle_dirty+0x2d6/0x340 fs/ocfs2/journal.c:1034 Call Trace:  ocfs2_journal_shutdown+0x414/0xc30 fs/ocfs2/journal.c:1116  ocfs2_mount_volume fs/ocfs2/super.c:1785 [inline]  ocfs2_fill_super+0x30a9/0x3cd0 fs/ocfs2/super.c:1083  get_tree_bdev_flags+0x38b/0x640 fs/super.c:1698  get_tree_bdev+0x24/0x40 fs/super.c:1721  ocfs2_get_tree+0x21/0x30 fs/ocfs2/super.c:1184  vfs_get_tree+0x9a/0x370 fs/super.c:1758  fc_mount fs/namespace.c:1199 [inline]  do_new_mount_fc fs/namespace.c:3642 [inline]  do_new_mount fs/namespace.c:3718 [inline]  path_mount+0x5b8/0x1ea0 fs/namespace.c:4028  do_mount fs/namespace.c:4041 [inline]  __do_sys_mount fs/namespace.c:4229 [inline]  __se_sys_mount fs/namespace.c:4206 [inline]  __x64_sys_mount+0x282/0x320 fs/namespace.c:4206  ...  [CAUSE] ocfs2_journal_toggle_dirty() used to return -EIO when journal-\u003ej_bh no longer contained a valid dinode, because the startup and shutdown paths already handled that failure. Commit 10995aa2451a (\"ocfs2: Morph the haphazard OCFS2_IS_VALID_DINODE() checks.\") changed the check to a BUG_ON() under the assumption that the journal dinode had already been validated. That turns an unexpected invalid journal dinode during mount teardown into a kernel crash instead of a normal mount failure.  [FIX] Replace the BUG_ON() with WARN_ON() and return -EIO. This keeps the invariant warning for debugging, but restores the original behavior of failing startup or shutdown cleanly instead of panicking the kernel.",
  "id": "DEBIAN-CVE-2026-80644",
  "modified": "2026-09-14T16:47:47.872533872Z",
  "published": "2026-08-28T08:16:49.290Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80644"
    }
  ],
  "upstream": [
    "CVE-2026-80644"
  ]
}