{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90320","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.802Z","datePublished":"2026-09-17T16:08:37.497Z","dateUpdated":"2026-09-18T17:54:33.902Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:33.902Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate external xattr entries when reading metadata\n\nocfs2_validate_xattr_block() checks the xattr block header before the\nblock reaches higher-level xattr users, but it does not verify that a\nnon-indexed block's xh_count and entry offsets fit inside the block. \nIndexed buckets likewise reach list/get consumers after ECC without an\nentry-bounds check.\n\nUse the flat xattr entry validator for non-indexed external xattr blocks,\nand use a bucket-specific validator for indexed buckets at metadata read\ntime.  The bucket validator keeps the entry array bounded by the first\nbucket block while checking name/value offsets against the bucket block\nthey target.\n\nReject corrupted external xattr metadata before listxattr() or getxattr()\ncan walk out-of-range entry arrays or name/value offsets.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in ocfs2_xattr_list_entries+0xd7/0x190\nRead of size 1 at addr ffff88810a654007 by task ocfs2_xattr_lis/630\nCall Trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  kasan_report+0xe0/0x110\n  ocfs2_xattr_list_entries+0xd7/0x190\n  ocfs2_listxattr+0x3f6/0x610\n  listxattr+0x90/0xe0\n  path_listxattrat+0xed/0x220\n  do_syscall_64+0x115/0x6a0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled bytes are on-disk ocfs2_xattr_header.xh_count and ocfs2_xattr_entry.xe_name_offset in an external xattr block or bucket, read by ocfs2_read_xattr_block()/ocfs2_read_xattr_bucket() when path_listxattrat() reaches ocfs2_listxattr()→ocfs2_xattr_block_list(); no network protocol carries those fields.\nAC:L - The crafted image fully controls xh_count and xe_name_offset; once the volume is mounted, ocfs2_xattr_list_entries() walks header->xh_entries[i] and forms name from xe_name_offset with no race, matching the deterministic KASAN UAF in that function.\nPR:N - ocfs2_xa_set() writes well-formed entry arrays, so planting a bad xh_count needs a crafted image; ocfs2_fs_type has no FS_USERNS_MOUNT, so the attacker cannot self-mount, and after the victim's ocfs2_fill_super() vfs_listxattr() calls ocfs2_listxattr() with no MAY_READ/DAC check.\nUI:R - The malformed external xattr header is inert until a victim or admin mounts the crafted OCFS2 image through ocfs2_fill_super(); listxattr/getxattr on that volume is the follow-on action that reaches ocfs2_xattr_list_entries() or ocfs2_xattr_block_get().\nS:U - The OOB/UAF is in kernel buffers for the ocfs2_xattr_block or xattr bucket on the same host that parsed the metadata and does not cross a VM, IOMMU, or guest-to-host boundary.\nC:H - ocfs2_xattr_list_entries() indexes xh_entries with unbounded on-disk xh_count, then memcpy's xe_name_len bytes from header+xe_name_offset into the listxattr buffer (copy_to_user); the repro is a KASAN UAF read of size 1 there, disclosing adjacent kernel memory.\nI:H - The same unvalidated xh_count/xe_name_offset are a kernel UAF/OOB walk; ocfs2_xa_bucket_add_entry() memmove's count*sizeof(ocfs2_xattr_entry) on setxattr and ocfs2_xattr_block_get() memcpy's xe_value_size from the unvalidated name offset, giving write/control-flow primitives.\nA:H - The KASAN report is a use-after-free in ocfs2_xattr_list_entries() from listxattr; the unbounded xh_count walk and ocfs2_xattr_bucket_get_name_value() indexing bu_bhs[name_offset>>blocksize_bits] past bu_blocks can oops or panic the node."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/xattr.c"],"versions":[{"version":"cf1d6c763fbcb115263114302485ad17e7933d87","lessThan":"9f4129b6905b7d638bbc9eb8013c3989cbe30b7e","status":"affected","versionType":"git"},{"version":"cf1d6c763fbcb115263114302485ad17e7933d87","lessThan":"2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/xattr.c"],"versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9f4129b6905b7d638bbc9eb8013c3989cbe30b7e"},{"url":"https://git.kernel.org/stable/c/2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6"}],"title":"ocfs2: validate external xattr entries when reading metadata","x_generator":{"engine":"bippy-1.2.0"}}}}