Impact
The vulnerability arises from an out‑of‑bounds read in the ext4 file system’s inline directory handling routine. When a directory listing operation (getdents64) requests entries from an inline directory, the kernel miscalculates the bounds of the inline buffer and reads a dirent header past its end, causing a slab‑level out‑of‑bounds read. This can expose portions of kernel memory to an attacker, potentially revealing sensitive data or the kernel’s internal state. The weakness is a classic buffer over‑read that falls under the category of improper bounds checking.
Affected Systems
All Linux kernel versions that have not incorporated the patch referenced in the commit URLs are vulnerable. This includes any kernel that still uses the ext4 inline directory code path as described, regardless of distribution or build. The specific products affected are the Linux kernel itself.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity risk, and the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local user performing a directory listing on an ext4 filesystem that contains inline directories, as the fault is triggered by the getdents64 system call. This inference is drawn from the description; the data does not state any requirement for higher privileges. Exploitation would result in kernel memory disclosure, not privilege escalation, at this time.
OpenCVE Enrichment
Debian DLA
Debian DSA