Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89492

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ocfs2: validate directory-index entry counts when reading metadata<br /> <br /> ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and<br /> signature of an indexed-directory block before it reaches higher-level<br /> callers, but neither validator bounds the ocfs2_dx_entry_list counts<br /> against the capacity of the block that holds them.<br /> <br /> ocfs2_dx_dir_search() then walks<br /> <br /> for (i = 0; i de_num_used); i++)<br /> dx_entry = &amp;entry_list-&gt;de_entries[i];<br /> <br /> over de_num_used entries with no bounds check. entry_list is either<br /> dx_leaf-&gt;dl_list (from ocfs2_read_dx_leaf) or, for an inline root,<br /> dx_root-&gt;dr_entries. A crafted on-disk image can set de_num_used (and<br /> de_count, which is the __counted_by_le() bound of de_entries) to 0xffff<br /> and make the walk read far past the end of the 4KB metadata block, giving<br /> a slab out-of-bounds read reachable from any path lookup, stat() or open()<br /> on an indexed directory once the image is mounted.<br /> <br /> Commit 775c17386a6f ("ocfs2: validate dx_root extent list fields during<br /> block read") already bounds dr_list for the non-inline dx_root, but left<br /> the inline dr_entries path and the dx_leaf dl_list unchecked. Add the<br /> same read-time validation for both entry lists: de_count must equal the<br /> capacity of the block (ocfs2_dx_entries_per_leaf()/per_root()) and<br /> de_num_used must not exceed de_count, rejecting corrupted metadata with<br /> -EFSCORRUPTED before ocfs2_dx_dir_search() can walk an out-of-range entry<br /> array.<br /> <br /> de_count is always written as exactly the block capacity when a leaf or<br /> inline root is formatted, so the equality check does not reject any valid<br /> image.<br /> <br /> Found by 0sec automated security-research tooling (https://0sec.ai).