AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72225

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's jbd2 journaling subsystem, specifically in the jbd2_journal_initialize_fast_commit() function, where an integer underflow can occur due to improper validation of journal capacity. This flaw can lead to corruption of critical journal parameters, potentially resulting in journal aborts and data integrity issues. Organizations using Linux systems with jbd2 should prioritize addressing this vulnerability to maintain data reliability and prevent potential system failures.

CVE
CVE-2026-72225
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() jbd2_journal_initialize_fast_commit() validates journal capacity by checking (journal->j_last - num_fc_blks < JBD2_MIN_JOURNAL_BLOCKS). Both j_last and num_fc_blks are unsigned, so when num_fc_blks exceeds j_last the subtraction wraps to a large value, bypassing the bounds check. The resulting underflow corrupts j_last, j_fc_first, and j_free, leading to journal abort. Fix by checking num_fc_blks against j_last before the subtraction, returning -EFSCORRUPTED.