{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89492","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.713Z","datePublished":"2026-09-11T19:43:44.137Z","dateUpdated":"2026-09-21T13:14:21.626Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-21T13:14:21.626Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate directory-index entry counts when reading metadata\n\nocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and\nsignature of an indexed-directory block before it reaches higher-level\ncallers, but neither validator bounds the ocfs2_dx_entry_list counts\nagainst the capacity of the block that holds them.\n\nocfs2_dx_dir_search() then walks\n\n\tfor (i = 0; i < le16_to_cpu(entry_list->de_num_used); i++)\n\t\tdx_entry = &entry_list->de_entries[i];\n\nover de_num_used entries with no bounds check.  entry_list is either\ndx_leaf->dl_list (from ocfs2_read_dx_leaf) or, for an inline root,\ndx_root->dr_entries.  A crafted on-disk image can set de_num_used (and\nde_count, which is the __counted_by_le() bound of de_entries) to 0xffff\nand make the walk read far past the end of the 4KB metadata block, giving\na slab out-of-bounds read reachable from any path lookup, stat() or open()\non an indexed directory once the image is mounted.\n\nCommit 775c17386a6f (\"ocfs2: validate dx_root extent list fields during\nblock read\") already bounds dr_list for the non-inline dx_root, but left\nthe inline dr_entries path and the dx_leaf dl_list unchecked.  Add the\nsame read-time validation for both entry lists: de_count must equal the\ncapacity of the block (ocfs2_dx_entries_per_leaf()/per_root()) and\nde_num_used must not exceed de_count, rejecting corrupted metadata with\n-EFSCORRUPTED before ocfs2_dx_dir_search() can walk an out-of-range entry\narray.\n\nde_count is always written as exactly the block capacity when a leaf or\ninline root is formatted, so the equality check does not reject any valid\nimage.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - OCFS2 sets s_export_op to ocfs2_export_ops and is commonly NFS-exported on shared cluster LUNs; remote nfsd LOOKUP/GETATTR/CREATE reach ocfs2_lookup→ocfs2_find_entry_dx→ocfs2_dx_dir_search (and create→ocfs2_dx_entry_list_insert) over the network with no local syscall on the server.\nAC:L - The attacker fully controls on-disk de_num_used and de_count in a dx_root or dx_leaf; inflating them above the fixed 4K-block capacity (e.g. 0xffff with de_num_used still below de_count) deterministically overflows the entry walk and insert with no race or attacker-uncontrollable layout.\nPR:N - Triggering needs only NFS LOOKUP or CREATE on an exported directory, including guest or anonymous NFS, or any unprivileged accessor of a mounted volume holding the forged index; planting malformed directory-index metadata on shared cluster storage does not require init-namespace root on the victim.\nUI:N - Once the OCFS2 volume is mounted and NFS-exported as a normal cluster or NAS deployment, the attacker triggers the overflow by their own LOOKUP, stat, open, or CREATE; no additional victim action such as mounting an image or opening a file is required.\nS:U - The overflow corrupts kernel memory and OCFS2 metadata on the host that parses the forged directory index; it does not escape a VM, bypass an IOMMU, or otherwise cross into a separate security authority.\nC:H - ocfs2_dx_dir_search walks de_num_used with no capacity check, so de_num_used of 0xffff reads far past the 4KB metadata block (up to about 1 MiB of adjacent kernel memory), an unbounded out-of-bounds read that enables high-impact disclosure.\nI:H - When de_count is inflated past block capacity and de_num_used is still less than de_count, create/mkdir calls ocfs2_dx_entry_list_insert and writes a dx_entry at de_entries[de_num_used] past the block; unlink memmove is similarly unbounded, yielding an attacker-triggered kernel out-of-bounds write.\nA:H - The unbounded out-of-bounds read on lookup and out-of-bounds write on create against kernel metadata buffers cause a kernel oops or panic, fully denying availability of the OCFS2 node until reboot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/dir.c"],"versions":[{"version":"9b7895efac906d66d19856194e1ba61f37e231a4","lessThan":"5e661f55ca8568471fce558effe81cca112f5cb2","status":"affected","versionType":"git"},{"version":"9b7895efac906d66d19856194e1ba61f37e231a4","lessThan":"fcfcba8fe17dbf2c8805690b8cc25e32d81249a4","status":"affected","versionType":"git"},{"version":"9b7895efac906d66d19856194e1ba61f37e231a4","lessThan":"b8a5c0c32df2c5b685ceef76ac77e37c7e1dc3ed","status":"affected","versionType":"git"},{"version":"9b7895efac906d66d19856194e1ba61f37e231a4","lessThan":"bc70726ddad53c7e9a9a85915bf2415b0d4f42f9","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/dir.c"],"versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5e661f55ca8568471fce558effe81cca112f5cb2"},{"url":"https://git.kernel.org/stable/c/fcfcba8fe17dbf2c8805690b8cc25e32d81249a4"},{"url":"https://git.kernel.org/stable/c/b8a5c0c32df2c5b685ceef76ac77e37c7e1dc3ed"},{"url":"https://git.kernel.org/stable/c/bc70726ddad53c7e9a9a85915bf2415b0d4f42f9"}],"title":"ocfs2: validate directory-index entry counts when reading metadata","x_generator":{"engine":"bippy-1.2.0"}}}}