CVE-2026-43067
published 2026-05-05CVE-2026-43067: In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks for indirect mapped blocks Commit…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
ext4: handle wraparound when searching for blocks for indirect mapped blocks
Commit 4865c768b563 ("ext4: always allocate blocks only from groups
inode can use") restricts what blocks will be allocated for indirect
block based files to block numbers that fit within 32-bit block
numbers.
However, when using a review bot running on the latest Gemini LLM to
check this commit when backporting into an LTS based kernel, it raised
this concern:
If ac->ac_g_ex.fe_group is >= ngroups (for instance, if the goal
group was populated via stream allocation from s_mb_last_groups),
then start will be >= ngroups.
Does this allow allocating blocks beyond the 32-bit limit for
indirect block mapped files? The commit message mentions that
ext4_mb_scan_groups_linear() takes care to not select unsupported
groups. However, its loop uses group = *start, and the very first
iteration will call ext4_mb_scan_group() with this unsupported
group because next_linear_group() is only called at the end of the
iteration.
After reviewing the code paths involved and considering the LLM
review, I determined that this can happen when there is a file system
where some files/directories are extent-mapped and others are
indirect-block mapped. To address this, add a safety clamp in
ext4_mb_scan_groups().
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 1b0edd6022a3f44ce87fea9959a9310f4628fbea < 83170a05908b6cf2fb3235d3065bf613ff866f3c | 83170a05908b6cf2fb3235d3065bf613ff866f3c |
| linux | linux | >= 321ed8d559c951e71ad2d2d69a4cf0445644e865 < 2a368ccddfc492a0aa951e2caef2985f20e96503 | 2a368ccddfc492a0aa951e2caef2985f20e96503 |
| linux | linux | >= 34c803edc0b3365a42efcf9815acab63b4cf54e0 < 12624c5b724a81e14e532972b40d863b0de3b7d1 | 12624c5b724a81e14e532972b40d863b0de3b7d1 |
| linux | linux | >= 4865c768b563deff1b6a6384e74a62f143427b42 < bb81702370fad22c06ca12b6e1648754dbc37e0f | bb81702370fad22c06ca12b6e1648754dbc37e0f |
| linux | linux | >= 5.15.203 < 5.16 | 5.16 |
| linux | linux | >= 6.1.167 < 6.1.168 | 6.1.168 |
| linux | linux | >= 6.12.77 < 6.12.80 | 6.12.80 |
| linux | linux | >= 6.18.14 < 6.18.21 | 6.18.21 |
| linux | linux | >= 6.19.4 < 6.19.11 | 6.19.11 |
| linux | linux | >= 6.6.130 < 6.6.134 | 6.6.134 |
| linux | linux | >= 9d89b9d55e25cb340c5b4b769876edc551b7a9ff < f89bba144938921a2249237ad04a0183ff3f8930 | f89bba144938921a2249237ad04a0183ff3f8930 |
| linux | linux | >= 9eea2f57d11b30049ff996ac3eff6e0dc8089e5f < 4bec4a498ce86314d470ae6144120461f2138c29 | 4bec4a498ce86314d470ae6144120461f2138c29 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 5.15.203 < 5.16 | 5.16 |
| linux | linux_kernel | >= 6.12.77 < 6.12.80 | 6.12.80 |
| linux | linux_kernel | >= 6.18.14 < 6.18.21 | 6.18.21 |
| linux | linux_kernel | >= 6.19.4 < 6.19.11 | 6.19.11 |
| linux | linux_kernel | >= 6.6.130 < 6.6.134 | 6.6.134 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-845x-q62g-4v8p: In the Linux kernel, the following vulnerability has been resolved:
ext4: handle wraparound when searching for blocks for indirect mapped blocks
Com
ghsa_unreviewed·2026-05-05
CVE-2026-43067 GHSA-845x-q62g-4v8p: In the Linux kernel, the following vulnerability has been resolved:
ext4: handle wraparound when searching for blocks for indirect mapped blocks
Com
In the Linux kernel, the following vulnerability has been resolved:
ext4: handle wraparound when searching for blocks for indirect mapped blocks
Commit 4865c768b563 ("ext4: always allocate blocks only from groups
inode can use") restricts what blocks will be allocated for indirect
block based files to block numbers that fit within 32-bit block
numbers.
However, when using a review bot running on the latest Gemini LLM to
check this commit when backporting into an LTS based kernel, it raised
this concern:
If ac->ac_g_ex.fe_group is >= ngroups (for instance, if the goal
group was populated via stream allocation from s_mb_last_groups),
then start will be >= ngroups.
Does this allow allocating blocks beyond the 32-bit limit for
indirect block mapped files? The commit message mentions that
VulDB
Linux Kernel up to 6.19.10 ext4_mb_scan_groups_linear infinite loop
vuldb·2026-05-05
CVE-2026-43067 [CRITICAL] Linux Kernel up to 6.19.10 ext4_mb_scan_groups_linear infinite loop
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.167/6.6.133/6.12.79/6.18.20/6.19.10. This affects the function ext4_mb_scan_groups_linear. The manipulation leads to infinite loop.
This vulnerability is uniquely identified as CVE-2026-43067. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
Red Hat
kernel: ext4: handle wraparound when searching for blocks for indirect mapped blocks
vendor_redhat·2026-05-05·CVSS 5.5
CVE-2026-43067 [MEDIUM] CWE-190 kernel: ext4: handle wraparound when searching for blocks for indirect mapped blocks
kernel: ext4: handle wraparound when searching for blocks for indirect mapped blocks
A flaw was found in the ext4 filesystem within the Linux kernel. This vulnerability involves an issue where the system incorrectly handles block allocation for indirect mapped files, potentially allowing blocks to be allocated beyond their defined 32-bit limit. This could lead to data corruption or system instability.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix deferred
Package: ker
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/12624c5b724a81e14e532972b40d863b0de3b7d1https://git.kernel.org/stable/c/2a368ccddfc492a0aa951e2caef2985f20e96503https://git.kernel.org/stable/c/4bec4a498ce86314d470ae6144120461f2138c29https://git.kernel.org/stable/c/83170a05908b6cf2fb3235d3065bf613ff866f3chttps://git.kernel.org/stable/c/bb81702370fad22c06ca12b6e1648754dbc37e0fhttps://git.kernel.org/stable/c/f89bba144938921a2249237ad04a0183ff3f8930
2026-05-05
Published