{"apiVersion":"1.0","identifier":"CVE-2026-80638","description":"In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent [BUG] Unlinking a refcounted file whose refcount tree has leaf blocks triggers a fortify panic due to an out-of-bounds write. [CAUSE] When the last leaf block is removed from a refcount tree, ocfs2_remove_refcount_extent() converts the root back to leaf mode with a bulk memset on &rb->rf_records. rf_records sits in an anonymous union with rf_list. rf_list.l_tree_depth aliases rf_records.rl_count, and is 0 for a single-level tree. With rl_count equal to 0, the memset writes past the 16-byte declared size of rf_records, which the fortify checker catches. [FIX] Replace the bulk memset on &rb->rf_records with a correctly-bounded memset on rl_recs[] alone, after setting rl_count to the correct value.","publishedAt":"2026-08-28T08:16:48","lastModifiedAt":"2026-08-28T08:16:48","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80638","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00155,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-80638","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-80638","en":"https://www.redsauce.net/en/cves/CVE-2026-80638","fr":"https://www.redsauce.net/fr/cves/CVE-2026-80638","pt":"https://www.redsauce.net/pt/cves/CVE-2026-80638","de":"https://www.redsauce.net/de/cves/CVE-2026-80638","sk":"https://www.redsauce.net/sk/cves/CVE-2026-80638","el":"https://www.redsauce.net/el/cves/CVE-2026-80638"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-80638"}}