{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92499","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-16T12:21:13.871Z","datePublished":"2026-09-17T16:10:13.391Z","dateUpdated":"2026-09-17T16:10:13.391Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:10:13.391Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate readdir offset before accessing dirent\n\nA corrupted directory can trigger the following KASAN report when\next4_readdir() resumes from an invalid position:\n\n  BUG: KASAN: use-after-free in __ext4_check_dir_entry+0x5ef/0x820\n  Read of size 2 at addr ffff88810a646000 by task repro_linear/509\n\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x53/0x70\n   print_report+0xd0/0x630\n   kasan_report+0xce/0x100\n   __ext4_check_dir_entry+0x5ef/0x820\n   ext4_readdir+0xcde/0x2b70\n   iterate_dir+0x1a1/0x520\n   __x64_sys_getdents64+0x12b/0x220\n   do_syscall_64+0xf9/0x540\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   </TASK>\n\nKASAN reports use-after-free because the out-of-bounds access lands in an\nadjacent freed page. The directory buffer itself is still referenced.\n\next4_dir_llseek() invalidates the directory cookie so that ext4_readdir()\nrescans directory entries from the start of the block. The rescan checks\nonly the lower bound of rec_len before advancing. A corrupted rec_len can\ntherefore place the offset where the block has insufficient space for a\ncomplete directory entry. The rescan itself may dereference that truncated\nentry, or the main loop may pass it to __ext4_check_dir_entry(). The latter\nreads de->rec_len before validating the range. For example:\n\n  block offset  0                           4092  4096\n                |---- de1.rec_len = 4092 -----|----|\n                                               de2.inode\n                                                    | de2.rec_len\n                                                    ^ OOB, reported as UAF\n\nde2 starts at offset 4092 in this 4 KiB block. Its four-byte inode fits in\nthe block, but its rec_len starts at offset 4096 and crosses the boundary.\n\nThe minimum safe length is inode-dependent. Encrypted and casefolded\ndirectory entries need eight additional hash bytes, while a valid metadata\nchecksum tail is only 12 bytes.\n\nCache the metadata checksum feature state and derive the minimum directory\nentry length from the on-disk format. Use it to bound both the rescan and\nthe offset passed to the main loop. Report an offset in a truncated block\ntail and skip the remainder of the block, while continuing to accept an\noffset exactly at the block boundary."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ext4/dir.c"],"versions":[{"version":"ac27a0ec112a089f1a5102bc8dffc79c8c815571","lessThan":"64d445d40e5ea4c4d4d88880db753b370cb69161","status":"affected","versionType":"git"},{"version":"ac27a0ec112a089f1a5102bc8dffc79c8c815571","lessThan":"b4c728577933753180e3e97f08424d5bcaff705e","status":"affected","versionType":"git"},{"version":"ac27a0ec112a089f1a5102bc8dffc79c8c815571","lessThan":"bc4b7b0414c33b2c8898eb04386df0d21a13dad8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ext4/dir.c"],"versions":[{"version":"2.6.19","status":"affected"},{"version":"0","lessThan":"2.6.19","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/64d445d40e5ea4c4d4d88880db753b370cb69161"},{"url":"https://git.kernel.org/stable/c/b4c728577933753180e3e97f08424d5bcaff705e"},{"url":"https://git.kernel.org/stable/c/bc4b7b0414c33b2c8898eb04386df0d21a13dad8"}],"title":"ext4: validate readdir offset before accessing dirent","x_generator":{"engine":"bippy-1.2.0"}}}}