Description
In the Linux kernel, the following vulnerability has been resolved:

ext4: fix out-of-bounds read in ext4_read_inline_dir()

ext4_read_inline_dir() can read a dirent header past the end of its inline
buffer, triggering a slab-out-of-bounds read during getdents64():

BUG: KASAN: slab-out-of-bounds in __ext4_check_dir_entry
Read of size 2 at addr ffff88800f3dd23c by task exploit/148
...
__ext4_check_dir_entry
ext4_read_inline_dir
iterate_dir

The dirent payload lives in a buffer of exactly inline_size bytes:

dir_buf = kmalloc(inline_size, GFP_NOFS);

but iteration runs in a position space extra_offset bytes larger
(extra_size = extra_offset + inline_size) so the synthetic "." and ".."
land at their block-dir offsets. A dirent is formed at "dir_buf + pos -
extra_offset", yet the ext4_check_dir_entry() length argument uses the
larger extra_size. A position whose dirent header would extend past
extra_size is therefore accepted, and the rescan loop's rec_len probe and
ext4_check_dir_entry() dereference de->rec_len before the entry is rejected.

Reject a position whose minimum-size dirent header would not fit within
extra_size before forming de, in both the rescan and main loops, and pass
inline_size rather than extra_size to ext4_check_dir_entry() so the length
check matches the physical buffer.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from an out‑of‑bounds read in the ext4 file system’s inline directory handling routine. When a directory listing operation (getdents64) requests entries from an inline directory, the kernel miscalculates the bounds of the inline buffer and reads a dirent header past its end, causing a slab‑level out‑of‑bounds read. This can expose portions of kernel memory to an attacker, potentially revealing sensitive data or the kernel’s internal state. The weakness is a classic buffer over‑read that falls under the category of improper bounds checking.

Affected Systems

All Linux kernel versions that have not incorporated the patch referenced in the commit URLs are vulnerable. This includes any kernel that still uses the ext4 inline directory code path as described, regardless of distribution or build. The specific products affected are the Linux kernel itself.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity risk, and the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local user performing a directory listing on an ext4 filesystem that contains inline directories, as the fault is triggered by the getdents64 system call. This inference is drawn from the description; the data does not state any requirement for higher privileges. Exploitation would result in kernel memory disclosure, not privilege escalation, at this time.

Generated by OpenCVE AI on September 20, 2026 at 05:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the ext4_read_inline_dir fix found in the provided commit references.
  • Reboot the system after applying the updated kernel to ensure the new code is active.
  • If an immediate kernel update is not possible, restrict or sandbox directory‑listing operations on ext4 filesystems that may contain inline directories to limit the opportunity for the fault to be triggered.

Generated by OpenCVE AI on September 20, 2026 at 05:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 18 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Wed, 16 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Wed, 16 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_dir() ext4_read_inline_dir() can read a dirent header past the end of its inline buffer, triggering a slab-out-of-bounds read during getdents64(): BUG: KASAN: slab-out-of-bounds in __ext4_check_dir_entry Read of size 2 at addr ffff88800f3dd23c by task exploit/148 ... __ext4_check_dir_entry ext4_read_inline_dir iterate_dir The dirent payload lives in a buffer of exactly inline_size bytes: dir_buf = kmalloc(inline_size, GFP_NOFS); but iteration runs in a position space extra_offset bytes larger (extra_size = extra_offset + inline_size) so the synthetic "." and ".." land at their block-dir offsets. A dirent is formed at "dir_buf + pos - extra_offset", yet the ext4_check_dir_entry() length argument uses the larger extra_size. A position whose dirent header would extend past extra_size is therefore accepted, and the rescan loop's rec_len probe and ext4_check_dir_entry() dereference de->rec_len before the entry is rejected. Reject a position whose minimum-size dirent header would not fit within extra_size before forming de, in both the rescan and main loops, and pass inline_size rather than extra_size to ext4_check_dir_entry() so the length check matches the physical buffer.
Title ext4: fix out-of-bounds read in ext4_read_inline_dir()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:38:36.340Z

Reserved: 2026-09-11T19:38:34.766Z

Link: CVE-2026-89786

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T09:17:09.330

Modified: 2026-09-16T15:18:08.860

Link: CVE-2026-89786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer