๐Ÿ” CVE Alert

CVE-2026-89787

UNKNOWN 0.0

ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() For casefolded encrypted directories ext4 stores an 8-byte hash trailer after the name (EXT4_DIRENT_HASHES()), at an offset derived from de->name_len. On the sb_no_casefold_compat_fallback() path ext4_match() reads that trailer, but ext4_search_dir()'s by-hand pre-check only tests de->name + de->name_len <= dlimit, which proves the name fits, not the rounded trailer. A crafted entry whose name ends at the block boundary passes the check while EXT4_DIRENT_HASHES(de) lands past the block end, so ext4_match() reads out of bounds on an ordinary lookup. KASAN reports it as a use-after-free when the page after the directory block holds a freed object: BUG: KASAN: use-after-free in ext4_match (fs/ext4/namei.c:1435) Read of size 4 at addr ffff888010458000 by task exploit Call Trace: ext4_match (fs/ext4/namei.c:1435) ext4_search_dir (fs/ext4/namei.c:1470) __ext4_find_entry (fs/ext4/namei.c:1268 fs/ext4/namei.c:1632) ext4_lookup (fs/ext4/namei.c:1703 fs/ext4/namei.c:1769) ... filename_lookup (fs/namei.c:2842) vfs_statx (fs/stat.c:353) __do_sys_newfstatat (fs/stat.c:538) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Require, for hash-in-dirent directories, that the whole entry including the rounded trailer fits before calling ext4_match(). This is the same bound ext4_check_dir_entry() already enforces via ext4_dir_rec_len(), so no well-formed entry is rejected. The other caller, ext4_find_dest_de(), runs ext4_check_dir_entry() first and is unaffected.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
471fbbea7ff7061b2d6474665cb5a2ceb4fd6500 < 4d20106c536b73c4a8a02652dc85e35898baebf7 471fbbea7ff7061b2d6474665cb5a2ceb4fd6500 < 61a395967de06edba58760e81907a272db749faa 471fbbea7ff7061b2d6474665cb5a2ceb4fd6500 < e94676a08af6312aa72d8a981232b281f9bcfcf5 471fbbea7ff7061b2d6474665cb5a2ceb4fd6500 < d8c184bec24b5a00ae96d704856d935eaded1685 471fbbea7ff7061b2d6474665cb5a2ceb4fd6500 < 3933884bc3102898b458c53fbd1ac52eb9cdb8a4 471fbbea7ff7061b2d6474665cb5a2ceb4fd6500 < 83663c0b739480c00cfe785675db87520ec484ed 471fbbea7ff7061b2d6474665cb5a2ceb4fd6500 < c7e6b863d298f56522d0d08554bbea7f142e6588
Linux / Linux
5.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4d20106c536b73c4a8a02652dc85e35898baebf7 git.kernel.org: https://git.kernel.org/stable/c/61a395967de06edba58760e81907a272db749faa git.kernel.org: https://git.kernel.org/stable/c/e94676a08af6312aa72d8a981232b281f9bcfcf5 git.kernel.org: https://git.kernel.org/stable/c/d8c184bec24b5a00ae96d704856d935eaded1685 git.kernel.org: https://git.kernel.org/stable/c/3933884bc3102898b458c53fbd1ac52eb9cdb8a4 git.kernel.org: https://git.kernel.org/stable/c/83663c0b739480c00cfe785675db87520ec484ed git.kernel.org: https://git.kernel.org/stable/c/c7e6b863d298f56522d0d08554bbea7f142e6588