Description
In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate external xattr entries when reading metadata

ocfs2_validate_xattr_block() checks the xattr block header before the
block reaches higher-level xattr users, but it does not verify that a
non-indexed block's xh_count and entry offsets fit inside the block.
Indexed buckets likewise reach list/get consumers after ECC without an
entry-bounds check.

Use the flat xattr entry validator for non-indexed external xattr blocks,
and use a bucket-specific validator for indexed buckets at metadata read
time. The bucket validator keeps the entry array bounded by the first
bucket block while checking name/value offsets against the bucket block
they target.

Reject corrupted external xattr metadata before listxattr() or getxattr()
can walk out-of-range entry arrays or name/value offsets.

Validation reproduced this kernel report:
BUG: KASAN: use-after-free in ocfs2_xattr_list_entries+0xd7/0x190
Read of size 1 at addr ffff88810a654007 by task ocfs2_xattr_lis/630
Call Trace:
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x630
kasan_report+0xe0/0x110
ocfs2_xattr_list_entries+0xd7/0x190
ocfs2_listxattr+0x3f6/0x610
listxattr+0x90/0xe0
path_listxattrat+0xed/0x220
do_syscall_64+0x115/0x6a0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that can lead to arbitrary code execution or privilege escalation
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, OCFS2 lacks proper validation of external extended attribute (xattr) metadata when reading. Specifically, ocfs2_validate_xattr_block does not ensure that non-indexed blocks’ header counts and offsets fit within the block, and indexed buckets skip bounds checks after ECC verification. This omission allows a corrupted xattr block to reference out‑of-range entry arrays or name/value offsets, which can trigger a use‑after‑free and potentially arbitrary kernel memory corruption. The issue was demonstrated by a KASAN report showing a read past the end of an xattr entry array during listxattr. Such memory corruption could be leveraged by an attacker to inject code or gain elevated privileges.

Affected Systems

The vulnerability affects the Linux operating system and its kernel implementation of the OCFS2 filesystem. No specific kernel version ranges are listed in the advisory, so any installation relying on an unpatched OCFS2 module may be susceptible.

Risk and Exploitability

The CVSS score of 7.8 classifies this as a high‑severity flaw. The EPSS score of less than 1% indicates a very low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, an attacker with the ability to craft or modify external xattr entries on an OCFS2 volume—which may be possible in a local or networked environment—could trigger the out‑of‑bounds read and potentially execute arbitrary code. The lack of a bounds check makes the issue exploitable with relatively simple privilege without needing additional system compromise. Based on the description, it is inferred that the attacker would need the ability to manipulate external xattr entries on an OCFS2 volume to trigger the flaw.

Generated by OpenCVE AI on September 19, 2026 at 15:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the bounds validation for OCFS2 external xattr blocks.
  • If an immediate kernel upgrade cannot be performed, avoid mounting or accessing OCFS2 volumes until the fix is applied to prevent corruption from being triggered.
  • Monitor the system for KASAN or kernel integrity errors that may indicate attempts to abuse the flaw.

Generated by OpenCVE AI on September 19, 2026 at 15:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate external xattr entries when reading metadata ocfs2_validate_xattr_block() checks the xattr block header before the block reaches higher-level xattr users, but it does not verify that a non-indexed block's xh_count and entry offsets fit inside the block. Indexed buckets likewise reach list/get consumers after ECC without an entry-bounds check. Use the flat xattr entry validator for non-indexed external xattr blocks, and use a bucket-specific validator for indexed buckets at metadata read time. The bucket validator keeps the entry array bounded by the first bucket block while checking name/value offsets against the bucket block they target. Reject corrupted external xattr metadata before listxattr() or getxattr() can walk out-of-range entry arrays or name/value offsets. Validation reproduced this kernel report: BUG: KASAN: use-after-free in ocfs2_xattr_list_entries+0xd7/0x190 Read of size 1 at addr ffff88810a654007 by task ocfs2_xattr_lis/630 Call Trace: dump_stack_lvl+0x66/0xa0 print_report+0xce/0x630 kasan_report+0xe0/0x110 ocfs2_xattr_list_entries+0xd7/0x190 ocfs2_listxattr+0x3f6/0x610 listxattr+0x90/0xe0 path_listxattrat+0xed/0x220 do_syscall_64+0x115/0x6a0 entry_SYSCALL_64_after_hwframe+0x77/0x7f
Title ocfs2: validate external xattr entries when reading metadata
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:33.902Z

Reserved: 2026-09-11T19:38:34.802Z

Link: CVE-2026-90320

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:29.957

Modified: 2026-09-18T18:17:53.563

Link: CVE-2026-90320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer