CVE-2026-89492
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ocfs2: validate directory-index entry counts when reading metadata<br />
<br />
ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and<br />
signature of an indexed-directory block before it reaches higher-level<br />
callers, but neither validator bounds the ocfs2_dx_entry_list counts<br />
against the capacity of the block that holds them.<br />
<br />
ocfs2_dx_dir_search() then walks<br />
<br />
for (i = 0; i de_num_used); i++)<br />
dx_entry = &entry_list->de_entries[i];<br />
<br />
over de_num_used entries with no bounds check. entry_list is either<br />
dx_leaf->dl_list (from ocfs2_read_dx_leaf) or, for an inline root,<br />
dx_root->dr_entries. A crafted on-disk image can set de_num_used (and<br />
de_count, which is the __counted_by_le() bound of de_entries) to 0xffff<br />
and make the walk read far past the end of the 4KB metadata block, giving<br />
a slab out-of-bounds read reachable from any path lookup, stat() or open()<br />
on an indexed directory once the image is mounted.<br />
<br />
Commit 775c17386a6f ("ocfs2: validate dx_root extent list fields during<br />
block read") already bounds dr_list for the non-inline dx_root, but left<br />
the inline dr_entries path and the dx_leaf dl_list unchecked. Add the<br />
same read-time validation for both entry lists: de_count must equal the<br />
capacity of the block (ocfs2_dx_entries_per_leaf()/per_root()) and<br />
de_num_used must not exceed de_count, rejecting corrupted metadata with<br />
-EFSCORRUPTED before ocfs2_dx_dir_search() can walk an out-of-range entry<br />
array.<br />
<br />
de_count is always written as exactly the block capacity when a leaf or<br />
inline root is formatted, so the equality check does not reject any valid<br />
image.<br />
<br />
Found by 0sec automated security-research tooling (https://0sec.ai).
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA


