๐Ÿ” CVE Alert

CVE-2026-46094

UNKNOWN 0.0

ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access The bounds check for the next xattr entry in check_xattrs() uses (void *)next >= end, which allows next to point within sizeof(u32) bytes of end. On the next loop iteration, IS_LAST_ENTRY() reads 4 bytes via *(__u32 *)(entry), which can overrun the valid xattr region. For example, if next lands at end - 1, the check passes since next < end, but IS_LAST_ENTRY() reads 4 bytes starting at end - 1, accessing 3 bytes beyond the valid region. Fix this by changing the check to (void *)next + sizeof(u32) > end, ensuring there is always enough space for the IS_LAST_ENTRY() read on the subsequent iteration.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 27, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
3478c83cf26bbffd026ae6a56bcb1fe544f0834e < ab6da97bc310db35d4e4ef5354bc3ff626b0698c 3478c83cf26bbffd026ae6a56bcb1fe544f0834e < 5a5314d2387633a272a04d1bd8727f99058e4e68 3478c83cf26bbffd026ae6a56bcb1fe544f0834e < 537e065977022aa22f2c2503e8accaf16622e0fd 3478c83cf26bbffd026ae6a56bcb1fe544f0834e < 520986722dbf869c122252123fc161c7302eab7d 3478c83cf26bbffd026ae6a56bcb1fe544f0834e < eceafc31ea7b42c984ece10d79d505c0bb6615d5
Linux / Linux
6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ab6da97bc310db35d4e4ef5354bc3ff626b0698c git.kernel.org: https://git.kernel.org/stable/c/5a5314d2387633a272a04d1bd8727f99058e4e68 git.kernel.org: https://git.kernel.org/stable/c/537e065977022aa22f2c2503e8accaf16622e0fd git.kernel.org: https://git.kernel.org/stable/c/520986722dbf869c122252123fc161c7302eab7d git.kernel.org: https://git.kernel.org/stable/c/eceafc31ea7b42c984ece10d79d505c0bb6615d5