Answer in brief
CVE-2026-74349 records a Unknown severity vulnerability in ocfs2: reject FITRIM ranges shorter than a cluster. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-74349 records a Unknown severity vulnerability in ocfs2: reject FITRIM ranges shorter than a cluster. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <d903d59c0315f59bdf0214b4f13d71c9feb2c45c || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <441abb77222f155e8d931dbabb465466db01cfd7 || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <e652d0f5108e447b22da4249bcd23dd1b63c73dd || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <346314bb0cc2fc52b50b73d6ecc62e0217455c2e || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <06c0a0431b9856506fcd9b2c1b0c6136567d756d || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <3fa7139b5f42731a61f78c42433adae13f9adc21 || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <2c13e02592b918be7725ab5965e01ef4e46c4b57 || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <ca1afd88f5eaaff9168e1466e5401385edf59543 | d903d59c0315f59bdf0214b4f13d71c9feb2c45c, 441abb77222f155e8d931dbabb465466db01cfd7, e652d0f5108e447b22da4249bcd23dd1b63c73dd, 346314bb0cc2fc52b50b73d6ecc62e0217455c2e, 06c0a0431b9856506fcd9b2c1b0c6136567d756d, 3fa7139b5f42731a61f78c42433adae13f9adc21, 2c13e02592b918be7725ab5965e01ef4e46c4b57, ca1afd88f5eaaff9168e1466e5401385edf59543 |
| Linux/Linuxgeneric | 3.14 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shorter than a cluster ocfs2_trim_mainbm() trims the global bitmap in cluster units, but its too-short range validation only checks sb->s_blocksize. On filesystems with a cluster size larger than the block size, a FITRIM range that is at least one block but shorter than one cluster is accepted and shifted down to len == 0. The later start + len - 1 and len -= ... arithmetic then underflows and can drive trimming past the requested range. Reject ranges shorter than s_clustersize instead. That preserves the existing -EINVAL behavior for requests that cannot discard even one allocation unit and keeps zero-cluster trims out of the group walk.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <d903d59c0315f59bdf0214b4f13d71c9feb2c45c || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <441abb77222f155e8d931dbabb465466db01cfd7 || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <e652d0f5108e447b22da4249bcd23dd1b63c73dd || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <346314bb0cc2fc52b50b73d6ecc62e0217455c2e || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <06c0a0431b9856506fcd9b2c1b0c6136567d756d || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <3fa7139b5f42731a61f78c42433adae13f9adc21 || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <2c13e02592b918be7725ab5965e01ef4e46c4b57 || >=aa89762c54800208d5afdcd8e6bf124818f17fe0 <ca1afd88f5eaaff9168e1466e5401385edf59543 | d903d59c0315f59bdf0214b4f13d71c9feb2c45c, 441abb77222f155e8d931dbabb465466db01cfd7, e652d0f5108e447b22da4249bcd23dd1b63c73dd, 346314bb0cc2fc52b50b73d6ecc62e0217455c2e, 06c0a0431b9856506fcd9b2c1b0c6136567d756d, 3fa7139b5f42731a61f78c42433adae13f9adc21, 2c13e02592b918be7725ab5965e01ef4e46c4b57, ca1afd88f5eaaff9168e1466e5401385edf59543 |
| Linux/Linuxgeneric | 3.14 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shorter than a cluster ocfs2_trim_mainbm() trims the global bitmap in cluster units, but its too-short range validation only checks sb->s_blocksize. On filesystems with a cluster size larger than the block size, a FITRIM range that is at least one block but shorter than one cluster is accepted and shifted down to len == 0. The later start + len - 1 and len -= ... arithmetic then underflows and can drive trimming past the requested range. Reject ranges shorter than s_clustersize instead. That preserves the existing -EINVAL behavior for requests that cannot discard even one allocation unit and keeps zero-cluster trims out of the group walk.
Quoted source text, attributed separately from HOL analysis.