CVE-2026-80881

Invalid metadata propagation via stale buffer validation

Published Sep 4, 2026 · Updated Sep 4, 2026

Improper buffer validation in the Linux kernel OCFS2 implementation allows attackers to pass inconsistent metadata to upper layers. In ocfs2_read_blocks(), a shared buffer head can retain BH_Uptodate after validation fails because put_bh() does not necessarily release its final reference. Reachability requires OCFS2 to encounter inconsistent on-disk data; the announcement identifies no resulting crash, disclosure, or code execution.

CVSS severityUnavailable
Unscored
EPSS probability0.17%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Improper buffer validation in the Linux kernel OCFS2 implementation allows attackers to pass inconsistent metadata to upper layers. In ocfs2_read_blocks(), a shared buffer head can retain BH_Uptodate after validation fails because put_bh() does not necessarily release its final reference. Reachability requires OCFS2 to encounter inconsistent on-disk data; the announcement identifies no resulting crash, disclosure, or code execution.

The record

CVE
CVE-2026-80881
Published
Sep 4, 2026
Updated
Sep 4, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
Unavailable
Attack vector
Unavailable
Privileges
Unavailable

Timeline

How it unfolded

  1. Sep 4, 2026CVE publishedPublication date reported by the CVE source.
  2. Sep 4, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=01f93d5e36753fc4d06ec67f05ce78c9c6f2dd56
  2. Affected versionversion=4.14.157 <4.15
  3. Affected versionversion=4.19.87 <4.20
  4. Affected versionversion=4.20
  5. Affected versionversion=4.4.204 <4.5
  6. Affected versionversion=4.9.204 <4.10
  7. Affected versionversion=65cbd1279f4b999d56a838344a30642db24cd215
  8. Affected versionversion=6c150df9c2e80b5cf86f5a0d98beb7390ad63bfc
  9. Affected versionversion=97e1db17bc1ef4c2e1789bc9323c7be44fba53f8
  10. Affected versionversion=cf76c78595ca87548ca5e45c862ac9e0949c4687 <0e389fc290c350c67591abf4c367119f4689f310
  11. Affected versionversion=cf76c78595ca87548ca5e45c862ac9e0949c4687 <4ab17e328522a4df5fe0f0dcf39098118b1feeaa
  12. Affected versionversion=cf76c78595ca87548ca5e45c862ac9e0949c4687 <5927acb3e2c99985a14adecd9d1b67ba191c622d
  13. Affected versionversion=cf76c78595ca87548ca5e45c862ac9e0949c4687 <61f7a5acb3bf8fc97dad78f54b1e8d0e1c819766
  14. Affected versionversion=cf76c78595ca87548ca5e45c862ac9e0949c4687 <6371a07148ee979af22a9d6f4c277462953a9a4a
  15. Affected versionversion=cf76c78595ca87548ca5e45c862ac9e0949c4687 <9e7a057934cdd58e4cc94350bcfe5367bbee0f8e
  16. Affected versionversion=cf76c78595ca87548ca5e45c862ac9e0949c4687 <a4eae1499c760949a93459d11390bd1fd823d31d
  17. Affected versionversion=cf76c78595ca87548ca5e45c862ac9e0949c4687 <ecb3f9386f4353034caef77239473c627232db17

What conditions does exploitation require?

Attack vectorUnavailable in this record.
Required privilegesUnavailable in this record.

What is affected?

The Linux Kernel Organization · Linuxversion=01f93d5e36753fc4d06ec67f05ce78c9c6f2dd56; version=4.14.157 <4.15; version=4.19.87 <4.20; version=4.20; version=4.4.204 <4.5; version=4.9.204 <4.10; version=65cbd1279f4b999d56a838344a30642db24cd215; version=6c150df9c2e80b5cf86f5a0d98beb7390ad63bfc; version=97e1db17bc1ef4c2e1789bc9323c7be44fba53f8; version=cf76c78595ca87548ca5e45c862ac9e0949c4687 <0e389fc290c350c67591abf4c367119f4689f310; version=cf76c78595ca87548ca5e45c862ac9e0949c4687 <4ab17e328522a4df5fe0f0dcf39098118b1feeaa; version=cf76c78595ca87548ca5e45c862ac9e0949c4687 <5927acb3e2c99985a14adecd9d1b67ba191c622d; version=cf76c78595ca87548ca5e45c862ac9e0949c4687 <61f7a5acb3bf8fc97dad78f54b1e8d0e1c819766; version=cf76c78595ca87548ca5e45c862ac9e0949c4687 <6371a07148ee979af22a9d6f4c277462953a9a4a; version=cf76c78595ca87548ca5e45c862ac9e0949c4687 <9e7a057934cdd58e4cc94350bcfe5367bbee0f8e; version=cf76c78595ca87548ca5e45c862ac9e0949c4687 <a4eae1499c760949a93459d11390bd1fd823d31d; version=cf76c78595ca87548ca5e45c862ac9e0949c4687 <ecb3f9386f4353034caef77239473c627232db17

Published CVSS scores

No CVSS assessment is available in this record.

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
VectorUnavailable
PrivilegesUnavailable
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

No sourced classifications are available.

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo