← All Advisories

CVE-2026-89492

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89492

Key Details

CVECVE-2026-89492
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate directory-index entry counts when reading metadata

ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and

signature of an indexed-directory block before it reaches higher-level

callers, but neither validator bounds the ocfs2_dx_entry_list counts

against the capacity of the block that holds them.

ocfs2_dx_dir_search() then walks

for (i = 0; i < le16_to_cpu(entry_list->de_num_used); i++)

dx_entry = &entry_list->de_entries[i];

over de_num_used entries with no bounds check. entry_list is either

dx_leaf->dl_list (from ocfs2_read_dx_leaf) or, for an inline root,

dx_root->dr_entries. A crafted on-disk image can set de_num_used (and

de_count, which is the __counted_by_le() bound of de_entries) to 0xffff

and make the walk read far past the end of the 4KB metadata block, giving

a slab out-of-bounds read reachable from any path lookup, stat() or open()

on an indexed directory once the image is mounted.

Commit 775c17386a6f ("ocfs2: validate dx_root extent list fields during

block read") already bounds dr_list for the non-inline dx_root, but left

the inline dr_entries path and the dx_leaf dl_list unchecked. Add the

same read-time validation for both entry lists: de_count must equal the

capacity of the block (ocfs2_dx_entries_per_leaf()/per_root()) and

de_num_used must not exceed de_count, rejecting corrupted metadata with

-EFSCORRUPTED before ocfs2_dx_dir_search() can walk an out-of-range entry

array.

de_count is always written as exactly the block capacity when a leaf or

inline root is formatted, so the equality check does not reject any valid

image.

Found by 0sec automated security-research tooling (https://0sec.ai). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89492
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89492