Description
In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix readdir position truncation on 32-bit kernels

In ocfs2_dir_foreach_blk_el(), the directory cookie position is
rebuilt with

ctx->pos = (ctx->pos & ~(sb->s_blocksize - 1)) | offset;

`ctx->pos` is loff_t (signed 64-bit), while `sb->s_blocksize` is
unsigned long. On 32-bit kernels unsigned long is 32-bit, so the mask

~(sb->s_blocksize - 1)

is computed as a 32-bit unsigned value (e.g. 0xfffff000 for a 4 KiB
block size). In the AND expression with the 64-bit `ctx->pos`, that
unsigned operand is zero-extended to 64 bits per the usual arithmetic
conversions, yielding 0x00000000fffff000. The high 32 bits of
`ctx->pos` are silently cleared, even though directory size is
allowed to exceed 4 GiB.

When readdir() crosses the 4 GiB boundary on a 32-bit kernel the
position is reset back into the first 4 GiB block, making the
re-validation path re-enumerate already-returned dirents indefinitely.

This is ocfs2_dir_foreach_blk_el(), the extent-list readdir path taken
for all non-inline directories, so a directory large enough to cross
4 GiB reaches it.

This is the same class of bug that commit 3dce5bb82c97 ("exfat: Fix
bitwise operation having different size") fixed in exfat, and the
fix mirrors the equivalent ext4 fix in this series. Cast the operand
to loff_t so the mask is 64-bit before the AND:

ctx->pos = (ctx->pos & ~((loff_t)sb->s_blocksize - 1)) | offset;

64-bit kernels are unaffected.
Published: 2026-09-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service kernels
Action: Apply Patch
AI Analysis

Impact

The flaw in the Linux kernel’s ocfs2 filesystem is an integer truncation that occurs when recomputing the directory cookie position on 32‑bit kernels. The 64‑bit `loff_t` value of `ctx->pos` is bit‑masked against a 32‑bit block‑size pattern, which zero‑extends to 64 bits and silently clears the high 32 bits of the position. When a directory larger than 4 GiB is read, the readdir routine resets the position back into the first 4 GiB block and re‑enumerates already‑returned entries, causing an endless loop that stalls directory operations.

Affected Systems

All Linux kernel installations using the ocfs2 filesystem are affected. Any machine that mounts an ocfs2 volume containing a directory that crosses the 4‑GiB boundary on a 32‑bit kernel is vulnerable. 64‑bit kernels are unaffected, as are systems that never use ocfs2 or that keep all ocfs2 directories below 4 GiB.

Risk and Exploitability

The CVSS base score of 5.5 indicates moderate risk. The EPSS score of less than 1 % shows vulnerability is not listed in the CISA KEV catalog. An attacker would need local access to a process that performs readdir on a large ocfs2 directory; the impact is a denial‑of‑service through high CPU consumption, with no privilege escalation or remote code execution possible.

Generated by OpenCVE AI on September 15, 2026 at 22:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the ocfs2 readdir position truncation fix
  • On 32‑bit systems, avoid creating or accessing ocfs2 directories that exceed the 4‑GiB limit; consider switching to a different filesystem
  • Monitor CPU for repeated ls or similar commands that may indicate an infinite readdir loop

Generated by OpenCVE AI on September 15, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix readdir position truncation on 32-bit kernels In ocfs2_dir_foreach_blk_el(), the directory cookie position is rebuilt with ctx->pos = (ctx->pos & ~(sb->s_blocksize - 1)) | offset; `ctx->pos` is loff_t (signed 64-bit), while `sb->s_blocksize` is unsigned long. On 32-bit kernels unsigned long is 32-bit, so the mask ~(sb->s_blocksize - 1) is computed as a 32-bit unsigned value (e.g. 0xfffff000 for a 4 KiB block size). In the AND expression with the 64-bit `ctx->pos`, that unsigned operand is zero-extended to 64 bits per the usual arithmetic conversions, yielding 0x00000000fffff000. The high 32 bits of `ctx->pos` are silently cleared, even though directory size is allowed to exceed 4 GiB. When readdir() crosses the 4 GiB boundary on a 32-bit kernel the position is reset back into the first 4 GiB block, making the re-validation path re-enumerate already-returned dirents indefinitely. This is ocfs2_dir_foreach_blk_el(), the extent-list readdir path taken for all non-inline directories, so a directory large enough to cross 4 GiB reaches it. This is the same class of bug that commit 3dce5bb82c97 ("exfat: Fix bitwise operation having different size") fixed in exfat, and the fix mirrors the equivalent ext4 fix in this series. Cast the operand to loff_t so the mask is 64-bit before the AND: ctx->pos = (ctx->pos & ~((loff_t)sb->s_blocksize - 1)) | offset; 64-bit kernels are unaffected.
Title ocfs2: fix readdir position truncation on 32-bit kernels
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:25.670Z

Reserved: 2026-09-11T19:38:34.713Z

Link: CVE-2026-89490

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:30.810

Modified: 2026-09-14T13:19:05.950

Link: CVE-2026-89490

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:42Z

Links: CVE-2026-89490 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:45:07Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound