Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-72159

Published Aug 15, 2026 EPSS 0.21% (11th pctl)

Overview

CVE-2026-72159 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: reject non-inline dinodes with i_size and zero i_clusters

On a volume mounted without OCFS2_FEATURE_INCOMPAT_SPARSE_ALLOC, a

non-inline regular file with non-zero i_size and zero i_clusters is

structurally malformed: the extent map declares no allocated clusters yet

the size header claims content exists. Keep rejecting that shape, but

express it through a shared predicate so the same invariant is available

to normal inode reads and online filecheck.

The same zero-cluster shape is also malformed for non-inline directories.

ocfs2 directory growth allocates backing storage before advancing i_size,

and ocfs2_dir_foreach_blk_el() later walks until ctx->pos reaches

i_size_read(inode). A forged directory dinode with a huge i_size and no

clusters would repeatedly fail on holes while advancing through the

claimed size.

Sparse regular files remain exempt: on sparse-alloc volumes, truncate can

legitimately grow i_si

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-72159?

CVE-2026-72159 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-72159?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-72159?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-72159?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-72159 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.