{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90321","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.802Z","datePublished":"2026-09-17T16:08:38.138Z","dateUpdated":"2026-09-18T17:54:35.231Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:35.231Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate inline xattrs during inode block validation\n\nPatch series \"ocfs2: validate xattr entry bounds\", v7.\n\nThis series validates OCFS2 xattr entry name/value bounds when xattr\nmetadata is read and validated, before getxattr() or listxattr() can walk\nout-of-range entry arrays or offsets from corrupted metadata.\n\n\nThis patch (of 2):\n\nocfs2_validate_inode_block() verifies a dinode before OCFS2 users walk\nmetadata from it, but inline xattr metadata is still checked only in\noperation-specific consumers.  The existing ibody lookup helper validates\ninline header placement and entry count, but inode block validation does\nnot reject entry name/value bounds.\n\nAdd a flat xattr entry validator and call it from inode block validation\nfor inline xattrs.  Keep the operation paths on their existing\nheader/count lookup checks; the full entry bounds check now runs when the\ninode block is validated at read time.\n\nReject corrupted inline xattr metadata before ocfs2_xattr_ibody_get() or\nlistxattr() can walk past the inline storage.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in ocfs2_xattr_find_entry+0x5a/0x170\nRead of size 2 at addr ffff8881242a2000 by task python3/529\nCall Trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  kasan_report+0xe0/0x110\n  ocfs2_xattr_find_entry+0x5a/0x170\n  ocfs2_xattr_get_nolock+0x20a/0x820\n  ocfs2_xattr_get+0x10c/0x1e0\n  __vfs_getxattr+0xe2/0x130\n  vfs_getxattr+0x185/0x1b0"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The malformed bytes are dinode inline-xattr xe_name_offset, xe_name_len and xe_value_size, read from the inode block by ocfs2_read_inode_block() into ocfs2_validate_inode_block() and later walked by ocfs2_xattr_ibody_get()/ocfs2_xattr_ibody_list(); no o2net, NFS, or SMB message carries those offsets.\nAC:L - A crafted dinode with OCFS2_INLINE_XATTR_FL and attacker-chosen xe_name_offset/xe_value_size is sufficient; after mount, getxattr(2) reaches vfs_getxattr()→ocfs2_xattr_get()→ocfs2_xattr_find_entry() and hits the reported KASAN UAF with no race or other condition outside the attacker’s control.\nPR:N - ocfs2_fs_type.fs_flags has no FS_USERNS_MOUNT, so the attacker cannot self-mount; ocfs2_xa_set() writes well-formed inline entries, so planting a bad xe_name_offset needs a crafted image. After the victim’s ocfs2_fill_super(), listxattr(2) calls ocfs2_listxattr() with no MAY_READ/DAC check.\nUI:R - The inline xattr payload is inert until a victim mounts the crafted OCFS2 image through ocfs2_fill_super(); getxattr(2) or listxattr(2) on that volume is the follow-on action that reaches ocfs2_xattr_find_entry() or ocfs2_xattr_list_entries().\nS:U - The OOB/UAF is in the dinode buffer_head parsed by ocfs2_validate_inode_block() on the same host that mounted the volume and does not cross a VM, IOMMU, or guest-to-host boundary.\nC:H - ocfs2_xattr_list_entries() memcpy’s xe_name_len bytes from header+xe_name_offset into the listxattr buffer, and ocfs2_xattr_ibody_get() memcpy’s xe_value_size bytes from that same unvalidated offset into the getxattr buffer; the repro is a KASAN UAF read of size 2 in ocfs2_xattr_find_entry().\nI:H - The same unvalidated xe_name_offset/xe_value_size are a kernel UAF/OOB walk of the inline region; ocfs2_xa_block_wipe_namevalue() memmove’s from header+min(xe_name_offset) with namevalue_size_xe() taken from on-disk xe_value_size when setxattr reuses that entry, a heap write primitive.\nA:H - The KASAN report is a use-after-free in ocfs2_xattr_find_entry() from getxattr; namevalue_size_xe() BUG_ON()s when a local inline entry has xe_value_size > OCFS2_XATTR_INLINE_SIZE, and walking an out-of-range name/value offset can oops the node."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/inode.c","fs/ocfs2/xattr.c","fs/ocfs2/xattr.h"],"versions":[{"version":"cf1d6c763fbcb115263114302485ad17e7933d87","lessThan":"3fd45b24879fa4885b66a582a6e47eda67f11310","status":"affected","versionType":"git"},{"version":"cf1d6c763fbcb115263114302485ad17e7933d87","lessThan":"8914a3330b72378136c2c02d6328a826f6abdad7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/inode.c","fs/ocfs2/xattr.c","fs/ocfs2/xattr.h"],"versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3fd45b24879fa4885b66a582a6e47eda67f11310"},{"url":"https://git.kernel.org/stable/c/8914a3330b72378136c2c02d6328a826f6abdad7"}],"title":"ocfs2: validate inline xattrs during inode block validation","x_generator":{"engine":"bippy-1.2.0"}}}}