{"api_version":"1","generated_at":"2026-10-01T19:11:56+00:00","cve":"CVE-2026-90320","urls":{"html":"https://cve.report/CVE-2026-90320","api":"https://cve.report/api/cve/CVE-2026-90320.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90320","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90320"},"summary":{"title":"ocfs2: validate external xattr entries when reading metadata","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate external xattr entries when reading metadata\n\nocfs2_validate_xattr_block() checks the xattr block header before the\nblock reaches higher-level xattr users, but it does not verify that a\nnon-indexed block's xh_count and entry offsets fit inside the block. \nIndexed buckets likewise reach list/get consumers after ECC without an\nentry-bounds check.\n\nUse the flat xattr entry validator for non-indexed external xattr blocks,\nand use a bucket-specific validator for indexed buckets at metadata read\ntime.  The bucket validator keeps the entry array bounded by the first\nbucket block while checking name/value offsets against the bucket block\nthey target.\n\nReject corrupted external xattr metadata before listxattr() or getxattr()\ncan walk out-of-range entry arrays or name/value offsets.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in ocfs2_xattr_list_entries+0xd7/0x190\nRead of size 1 at addr ffff88810a654007 by task ocfs2_xattr_lis/630\nCall Trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  kasan_report+0xe0/0x110\n  ocfs2_xattr_list_entries+0xd7/0x190\n  ocfs2_listxattr+0x3f6/0x610\n  listxattr+0x90/0xe0\n  path_listxattrat+0xed/0x220\n  do_syscall_64+0x115/0x6a0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:29","updated_at":"2026-09-18 18:17:53"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6","name":"https://git.kernel.org/stable/c/2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/9f4129b6905b7d638bbc9eb8013c3989cbe30b7e","name":"https://git.kernel.org/stable/c/9f4129b6905b7d638bbc9eb8013c3989cbe30b7e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90320","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90320","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cf1d6c763fbcb115263114302485ad17e7933d87 9f4129b6905b7d638bbc9eb8013c3989cbe30b7e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cf1d6c763fbcb115263114302485ad17e7933d87 2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.28","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.28 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"90320","cve":"CVE-2026-90320","epss":"0.001620000","percentile":"0.058340000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/ocfs2/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"9f4129b6905b7d638bbc9eb8013c3989cbe30b7e","status":"affected","version":"cf1d6c763fbcb115263114302485ad17e7933d87","versionType":"git"},{"lessThan":"2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6","status":"affected","version":"cf1d6c763fbcb115263114302485ad17e7933d87","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/ocfs2/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.28"},{"lessThan":"2.6.28","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"2.6.28","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"2.6.28","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate external xattr entries when reading metadata\n\nocfs2_validate_xattr_block() checks the xattr block header before the\nblock reaches higher-level xattr users, but it does not verify that a\nnon-indexed block's xh_count and entry offsets fit inside the block. \nIndexed buckets likewise reach list/get consumers after ECC without an\nentry-bounds check.\n\nUse the flat xattr entry validator for non-indexed external xattr blocks,\nand use a bucket-specific validator for indexed buckets at metadata read\ntime.  The bucket validator keeps the entry array bounded by the first\nbucket block while checking name/value offsets against the bucket block\nthey target.\n\nReject corrupted external xattr metadata before listxattr() or getxattr()\ncan walk out-of-range entry arrays or name/value offsets.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in ocfs2_xattr_list_entries+0xd7/0x190\nRead of size 1 at addr ffff88810a654007 by task ocfs2_xattr_lis/630\nCall Trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  kasan_report+0xe0/0x110\n  ocfs2_xattr_list_entries+0xd7/0x190\n  ocfs2_listxattr+0x3f6/0x610\n  listxattr+0x90/0xe0\n  path_listxattrat+0xed/0x220\n  do_syscall_64+0x115/0x6a0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f"}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled bytes are on-disk ocfs2_xattr_header.xh_count and ocfs2_xattr_entry.xe_name_offset in an external xattr block or bucket, read by ocfs2_read_xattr_block()/ocfs2_read_xattr_bucket() when path_listxattrat() reaches ocfs2_listxattr()→ocfs2_xattr_block_list(); no network protocol carries those fields.\nAC:L - The crafted image fully controls xh_count and xe_name_offset; once the volume is mounted, ocfs2_xattr_list_entries() walks header->xh_entries[i] and forms name from xe_name_offset with no race, matching the deterministic KASAN UAF in that function.\nPR:N - ocfs2_xa_set() writes well-formed entry arrays, so planting a bad xh_count needs a crafted image; ocfs2_fs_type has no FS_USERNS_MOUNT, so the attacker cannot self-mount, and after the victim's ocfs2_fill_super() vfs_listxattr() calls ocfs2_listxattr() with no MAY_READ/DAC check.\nUI:R - The malformed external xattr header is inert until a victim or admin mounts the crafted OCFS2 image through ocfs2_fill_super(); listxattr/getxattr on that volume is the follow-on action that reaches ocfs2_xattr_list_entries() or ocfs2_xattr_block_get().\nS:U - The OOB/UAF is in kernel buffers for the ocfs2_xattr_block or xattr bucket on the same host that parsed the metadata and does not cross a VM, IOMMU, or guest-to-host boundary.\nC:H - ocfs2_xattr_list_entries() indexes xh_entries with unbounded on-disk xh_count, then memcpy's xe_name_len bytes from header+xe_name_offset into the listxattr buffer (copy_to_user); the repro is a KASAN UAF read of size 1 there, disclosing adjacent kernel memory.\nI:H - The same unvalidated xh_count/xe_name_offset are a kernel UAF/OOB walk; ocfs2_xa_bucket_add_entry() memmove's count*sizeof(ocfs2_xattr_entry) on setxattr and ocfs2_xattr_block_get() memcpy's xe_value_size from the unvalidated name offset, giving write/control-flow primitives.\nA:H - The KASAN report is a use-after-free in ocfs2_xattr_list_entries() from listxattr; the unbounded xh_count walk and ocfs2_xattr_bucket_get_name_value() indexing bu_bhs[name_offset>>blocksize_bits] past bu_blocks can oops or panic the node."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:54:33.902Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/9f4129b6905b7d638bbc9eb8013c3989cbe30b7e"},{"url":"https://git.kernel.org/stable/c/2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6"}],"title":"ocfs2: validate external xattr entries when reading metadata","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90320","datePublished":"2026-09-17T16:08:37.497Z","dateReserved":"2026-09-11T19:38:34.802Z","dateUpdated":"2026-09-18T17:54:33.902Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:29","lastModifiedDate":"2026-09-18 18:17:53","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90320","Ordinal":"1","Title":"ocfs2: validate external xattr entries when reading metadata","CVE":"CVE-2026-90320","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90320","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate external xattr entries when reading metadata\n\nocfs2_validate_xattr_block() checks the xattr block header before the\nblock reaches higher-level xattr users, but it does not verify that a\nnon-indexed block's xh_count and entry offsets fit inside the block. \nIndexed buckets likewise reach list/get consumers after ECC without an\nentry-bounds check.\n\nUse the flat xattr entry validator for non-indexed external xattr blocks,\nand use a bucket-specific validator for indexed buckets at metadata read\ntime.  The bucket validator keeps the entry array bounded by the first\nbucket block while checking name/value offsets against the bucket block\nthey target.\n\nReject corrupted external xattr metadata before listxattr() or getxattr()\ncan walk out-of-range entry arrays or name/value offsets.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in ocfs2_xattr_list_entries+0xd7/0x190\nRead of size 1 at addr ffff88810a654007 by task ocfs2_xattr_lis/630\nCall Trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  kasan_report+0xe0/0x110\n  ocfs2_xattr_list_entries+0xd7/0x190\n  ocfs2_listxattr+0x3f6/0x610\n  listxattr+0x90/0xe0\n  path_listxattrat+0xed/0x220\n  do_syscall_64+0x115/0x6a0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f","Type":"Description","Title":"ocfs2: validate external xattr entries when reading metadata"}]}}}