CVE-2026-89787
Received Received - Intake

Out-of-Bounds Read in Linux Kernel ext4 Filesystem

Vulnerability report for CVE-2026-89787, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() For casefolded encrypted directories ext4 stores an 8-byte hash trailer after the name (EXT4_DIRENT_HASHES()), at an offset derived from de->name_len. On the sb_no_casefold_compat_fallback() path ext4_match() reads that trailer, but ext4_search_dir()'s by-hand pre-check only tests de->name + de->name_len <= dlimit, which proves the name fits, not the rounded trailer. A crafted entry whose name ends at the block boundary passes the check while EXT4_DIRENT_HASHES(de) lands past the block end, so ext4_match() reads out of bounds on an ordinary lookup. KASAN reports it as a use-after-free when the page after the directory block holds a freed object: BUG: KASAN: use-after-free in ext4_match (fs/ext4/namei.c:1435) Read of size 4 at addr ffff888010458000 by task exploit Call Trace: ext4_match (fs/ext4/namei.c:1435) ext4_search_dir (fs/ext4/namei.c:1470) __ext4_find_entry (fs/ext4/namei.c:1268 fs/ext4/namei.c:1632) ext4_lookup (fs/ext4/namei.c:1703 fs/ext4/namei.c:1769) ... filename_lookup (fs/namei.c:2842) vfs_statx (fs/stat.c:353) __do_sys_newfstatat (fs/stat.c:538) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Require, for hash-in-dirent directories, that the whole entry including the rounded trailer fits before calling ext4_match(). This is the same bound ext4_check_dir_entry() already enforces via ext4_dir_rec_len(), so no well-formed entry is rejected. The other caller, ext4_find_dest_de(), runs ext4_check_dir_entry() first and is unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the ext4 filesystem. It involves a boundary check issue in ext4_search_dir() where a crafted directory entry could cause an out-of-bounds read when processing casefolded encrypted directories. The vulnerability occurs because the pre-check does not account for an 8-byte hash trailer that follows the directory name, leading to potential memory corruption.

Detection Guidance

This vulnerability is specific to the Linux kernel's ext4 filesystem and requires kernel memory corruption detection tools like KASAN. Check kernel logs for KASAN reports indicating use-after-free in ext4_match or ext4_search_dir functions. No network detection commands are applicable as this is a local filesystem vulnerability.

Impact Analysis

This vulnerability could allow an attacker to read sensitive memory or cause a system crash by exploiting a crafted directory entry. It may lead to unauthorized data access, privilege escalation, or denial-of-service conditions on affected systems running vulnerable Linux kernels.

Mitigation Strategies

Update your Linux kernel to the latest patched version that includes the fix for this ext4 vulnerability. If immediate patching is not possible, avoid using casefolded encrypted directories on ext4 filesystems as a temporary mitigation measure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89787. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart