{"id":"CVE-2026-89786","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-89786","generatedAt":"2026-09-20T13:18:42.446Z","title":"In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_dir() ext4_read_inline_dir() can read a dirent header past the end of its inline buffer, triggering a slab-out-of-bounds read during…","description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix out-of-bounds read in ext4_read_inline_dir()\n\next4_read_inline_dir() can read a dirent header past the end of its inline\nbuffer, triggering a slab-out-of-bounds read during getdents64():\n\n  BUG: KASAN: slab-out-of-bounds in __ext4_check_dir_entry\n  Read of size 2 at addr ffff88800f3dd23c by task exploit/148\n   ...\n   __ext4_check_dir_entry\n   ext4_read_inline_dir\n   iterate_dir\n\nThe dirent payload lives in a buffer of exactly inline_size bytes:\n\n\tdir_buf = kmalloc(inline_size, GFP_NOFS);\n\nbut iteration runs in a position space extra_offset bytes larger\n(extra_size = extra_offset + inline_size) so the synthetic \".\" and \"..\"\nland at their block-dir offsets. A dirent is formed at \"dir_buf + pos -\nextra_offset\", yet the ext4_check_dir_entry() length argument uses the\nlarger extra_size. A position whose dirent header would extend past\nextra_size is therefore accepted, and the rescan loop's rec_len probe and\next4_check_dir_entry() dereference de->rec_len before the entry is rejected.\n\nReject a position whose minimum-size dirent header would not fit within\nextra_size before forming de, in both the rescan and main loops, and pass\ninline_size rather than extra_size to ext4_check_dir_entry() so the length\ncheck matches the physical buffer.","published":"2026-09-16T09:17:09.000Z","lastModified":"2026-09-16T15:18:09.000Z","status":"Received","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","cvss":{"version":"3.1","score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},"cwe":[],"affected":[],"epss":{"score":0.00688,"percentile":0.51259,"date":"2026-09-19","history":[]},"kev":{"listed":false},"exploits":{"count":0,"verified":false,"firstPublished":null,"source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[]},"verdict":{"level":"high","text":"High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit."},"changes":[],"references":[{"url":"https://git.kernel.org/stable/c/1a1dea633b724a1c042dbcdb1fed27f410916688","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36bf17bb90cdf7a623499b624b05acde4d2feef5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5fd20d4e50dd6e460b3ea8e4396f8553d4526f8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6702c7da86d8cdb88d0fc57166286e115ffeb8c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9333cc809f0a89e001b814155a6cb8903a6274df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b060861f662d4826dc700a1c3584243bb3474cfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1e7c186555ad65554fd2f2b02f5a539aa35ae48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89786","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}