{"apiVersion":"1.0","identifier":"CVE-2026-72164","description":"In the Linux kernel, the following vulnerability has been resolved: ocfs2: avoid moving extents to occupied clusters For non-auto OCFS2_IOC_MOVE_EXT operations, userspace supplies a physical me_goal. ocfs2_move_extent() initializes new_phys_cpos from that goal and expects ocfs2_probe_alloc_group() to replace it with a free run in the target block group. The probe currently leaves *phys_cpos unchanged if the scan reaches the end of the group without finding a free run. An occupied goal at the last bit can therefore survive the probe and be passed to __ocfs2_move_extent(), which copies file data into a cluster still owned by another inode before the bitmap is updated. When the probe does find a free run, it also subtracts move_len from the ending bit. The start of an N-bit run ending at i is i - N + 1, so the current calculation can report the bit immediately before the free run. Clear *phys_cpos before scanning and use the correct free-run start. Callers already treat a zero result as -ENOSPC, so failed probes no longer continue with an occupied caller-controlled goal.","publishedAt":"2026-08-15T06:21:34","lastModifiedAt":"2026-08-17T06:18:16","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72164","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00164,"riskScore":0.79,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72164","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72164","en":"https://www.redsauce.net/en/cves/CVE-2026-72164","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72164","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72164","de":"https://www.redsauce.net/de/cves/CVE-2026-72164","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72164","el":"https://www.redsauce.net/el/cves/CVE-2026-72164"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72164"}}