CVE-2026-89490
Received Received - Intake

Integer Overflow in OCFS2 Directory Readdir on 32-bit Kernels

Vulnerability report for CVE-2026-89490, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix readdir position truncation on 32-bit kernels In ocfs2_dir_foreach_blk_el(), the directory cookie position is rebuilt with ctx->pos = (ctx->pos & ~(sb->s_blocksize - 1)) | offset; `ctx->pos` is loff_t (signed 64-bit), while `sb->s_blocksize` is unsigned long. On 32-bit kernels unsigned long is 32-bit, so the mask ~(sb->s_blocksize - 1) is computed as a 32-bit unsigned value (e.g. 0xfffff000 for a 4 KiB block size). In the AND expression with the 64-bit `ctx->pos`, that unsigned operand is zero-extended to 64 bits per the usual arithmetic conversions, yielding 0x00000000fffff000. The high 32 bits of `ctx->pos` are silently cleared, even though directory size is allowed to exceed 4 GiB. When readdir() crosses the 4 GiB boundary on a 32-bit kernel the position is reset back into the first 4 GiB block, making the re-validation path re-enumerate already-returned dirents indefinitely. This is ocfs2_dir_foreach_blk_el(), the extent-list readdir path taken for all non-inline directories, so a directory large enough to cross 4 GiB reaches it. This is the same class of bug that commit 3dce5bb82c97 ("exfat: Fix bitwise operation having different size") fixed in exfat, and the fix mirrors the equivalent ext4 fix in this series. Cast the operand to loff_t so the mask is 64-bit before the AND: ctx->pos = (ctx->pos & ~((loff_t)sb->s_blocksize - 1)) | offset; 64-bit kernels are unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle ocfs2 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the OCFS2 file system in the Linux kernel. On 32-bit systems, the directory position during readdir operations can be truncated due to incorrect bitwise operations. The position value, which is 64-bit, gets masked with a 32-bit value, clearing its high 32 bits. This causes the readdir function to reset to the start of the directory when it crosses the 4 GiB boundary, leading to infinite loops while re-enumerating already returned directory entries.

Detection Guidance

This vulnerability affects the OCFS2 filesystem on 32-bit Linux kernels. Detection requires checking the kernel version and OCFS2 filesystem usage. Run 'uname -a' to verify a 32-bit kernel and 'mount | grep ocfs2' to check if OCFS2 is mounted. If both conditions are true, the system is potentially vulnerable.

Impact Analysis

If you use a 32-bit Linux system with the OCFS2 file system and have directories larger than 4 GiB, this vulnerability could cause system hangs or excessive CPU usage. Applications reading large directories may get stuck in loops, leading to unresponsiveness or crashes.

Compliance Impact

This vulnerability affects data integrity in directory operations on 32-bit Linux kernels using OCFS2. It could lead to incomplete or incorrect data retrieval during directory traversal, potentially compromising audit trails or data access logs required by GDPR and HIPAA.

Mitigation Strategies

Upgrade to a patched Linux kernel version that includes the OCFS2 fix. If using a 32-bit kernel, consider migrating to a 64-bit kernel as 64-bit systems are unaffected. Ensure OCFS2 filesystem operations do not exceed 4 GiB directory sizes until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89490. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart