{"api_version":"1","generated_at":"2026-10-01T19:11:56+00:00","cve":"CVE-2026-90321","urls":{"html":"https://cve.report/CVE-2026-90321","api":"https://cve.report/api/cve/CVE-2026-90321.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90321","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90321"},"summary":{"title":"ocfs2: validate inline xattrs during inode block validation","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate inline xattrs during inode block validation\n\nPatch series \"ocfs2: validate xattr entry bounds\", v7.\n\nThis series validates OCFS2 xattr entry name/value bounds when xattr\nmetadata is read and validated, before getxattr() or listxattr() can walk\nout-of-range entry arrays or offsets from corrupted metadata.\n\n\nThis patch (of 2):\n\nocfs2_validate_inode_block() verifies a dinode before OCFS2 users walk\nmetadata from it, but inline xattr metadata is still checked only in\noperation-specific consumers.  The existing ibody lookup helper validates\ninline header placement and entry count, but inode block validation does\nnot reject entry name/value bounds.\n\nAdd a flat xattr entry validator and call it from inode block validation\nfor inline xattrs.  Keep the operation paths on their existing\nheader/count lookup checks; the full entry bounds check now runs when the\ninode block is validated at read time.\n\nReject corrupted inline xattr metadata before ocfs2_xattr_ibody_get() or\nlistxattr() can walk past the inline storage.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in ocfs2_xattr_find_entry+0x5a/0x170\nRead of size 2 at addr ffff8881242a2000 by task python3/529\nCall Trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  kasan_report+0xe0/0x110\n  ocfs2_xattr_find_entry+0x5a/0x170\n  ocfs2_xattr_get_nolock+0x20a/0x820\n  ocfs2_xattr_get+0x10c/0x1e0\n  __vfs_getxattr+0xe2/0x130\n  vfs_getxattr+0x185/0x1b0","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:30","updated_at":"2026-09-18 18:17:53"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/8914a3330b72378136c2c02d6328a826f6abdad7","name":"https://git.kernel.org/stable/c/8914a3330b72378136c2c02d6328a826f6abdad7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3fd45b24879fa4885b66a582a6e47eda67f11310","name":"https://git.kernel.org/stable/c/3fd45b24879fa4885b66a582a6e47eda67f11310","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90321","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90321","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cf1d6c763fbcb115263114302485ad17e7933d87 3fd45b24879fa4885b66a582a6e47eda67f11310 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cf1d6c763fbcb115263114302485ad17e7933d87 8914a3330b72378136c2c02d6328a826f6abdad7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.28","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.28 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"90321","cve":"CVE-2026-90321","epss":"0.001620000","percentile":"0.058110000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/ocfs2/inode.c","fs/ocfs2/xattr.c","fs/ocfs2/xattr.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"3fd45b24879fa4885b66a582a6e47eda67f11310","status":"affected","version":"cf1d6c763fbcb115263114302485ad17e7933d87","versionType":"git"},{"lessThan":"8914a3330b72378136c2c02d6328a826f6abdad7","status":"affected","version":"cf1d6c763fbcb115263114302485ad17e7933d87","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/ocfs2/inode.c","fs/ocfs2/xattr.c","fs/ocfs2/xattr.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.28"},{"lessThan":"2.6.28","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"2.6.28","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"2.6.28","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate inline xattrs during inode block validation\n\nPatch series \"ocfs2: validate xattr entry bounds\", v7.\n\nThis series validates OCFS2 xattr entry name/value bounds when xattr\nmetadata is read and validated, before getxattr() or listxattr() can walk\nout-of-range entry arrays or offsets from corrupted metadata.\n\n\nThis patch (of 2):\n\nocfs2_validate_inode_block() verifies a dinode before OCFS2 users walk\nmetadata from it, but inline xattr metadata is still checked only in\noperation-specific consumers.  The existing ibody lookup helper validates\ninline header placement and entry count, but inode block validation does\nnot reject entry name/value bounds.\n\nAdd a flat xattr entry validator and call it from inode block validation\nfor inline xattrs.  Keep the operation paths on their existing\nheader/count lookup checks; the full entry bounds check now runs when the\ninode block is validated at read time.\n\nReject corrupted inline xattr metadata before ocfs2_xattr_ibody_get() or\nlistxattr() can walk past the inline storage.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in ocfs2_xattr_find_entry+0x5a/0x170\nRead of size 2 at addr ffff8881242a2000 by task python3/529\nCall Trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  kasan_report+0xe0/0x110\n  ocfs2_xattr_find_entry+0x5a/0x170\n  ocfs2_xattr_get_nolock+0x20a/0x820\n  ocfs2_xattr_get+0x10c/0x1e0\n  __vfs_getxattr+0xe2/0x130\n  vfs_getxattr+0x185/0x1b0"}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The malformed bytes are dinode inline-xattr xe_name_offset, xe_name_len and xe_value_size, read from the inode block by ocfs2_read_inode_block() into ocfs2_validate_inode_block() and later walked by ocfs2_xattr_ibody_get()/ocfs2_xattr_ibody_list(); no o2net, NFS, or SMB message carries those offsets.\nAC:L - A crafted dinode with OCFS2_INLINE_XATTR_FL and attacker-chosen xe_name_offset/xe_value_size is sufficient; after mount, getxattr(2) reaches vfs_getxattr()→ocfs2_xattr_get()→ocfs2_xattr_find_entry() and hits the reported KASAN UAF with no race or other condition outside the attacker’s control.\nPR:N - ocfs2_fs_type.fs_flags has no FS_USERNS_MOUNT, so the attacker cannot self-mount; ocfs2_xa_set() writes well-formed inline entries, so planting a bad xe_name_offset needs a crafted image. After the victim’s ocfs2_fill_super(), listxattr(2) calls ocfs2_listxattr() with no MAY_READ/DAC check.\nUI:R - The inline xattr payload is inert until a victim mounts the crafted OCFS2 image through ocfs2_fill_super(); getxattr(2) or listxattr(2) on that volume is the follow-on action that reaches ocfs2_xattr_find_entry() or ocfs2_xattr_list_entries().\nS:U - The OOB/UAF is in the dinode buffer_head parsed by ocfs2_validate_inode_block() on the same host that mounted the volume and does not cross a VM, IOMMU, or guest-to-host boundary.\nC:H - ocfs2_xattr_list_entries() memcpy’s xe_name_len bytes from header+xe_name_offset into the listxattr buffer, and ocfs2_xattr_ibody_get() memcpy’s xe_value_size bytes from that same unvalidated offset into the getxattr buffer; the repro is a KASAN UAF read of size 2 in ocfs2_xattr_find_entry().\nI:H - The same unvalidated xe_name_offset/xe_value_size are a kernel UAF/OOB walk of the inline region; ocfs2_xa_block_wipe_namevalue() memmove’s from header+min(xe_name_offset) with namevalue_size_xe() taken from on-disk xe_value_size when setxattr reuses that entry, a heap write primitive.\nA:H - The KASAN report is a use-after-free in ocfs2_xattr_find_entry() from getxattr; namevalue_size_xe() BUG_ON()s when a local inline entry has xe_value_size > OCFS2_XATTR_INLINE_SIZE, and walking an out-of-range name/value offset can oops the node."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:54:35.231Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/3fd45b24879fa4885b66a582a6e47eda67f11310"},{"url":"https://git.kernel.org/stable/c/8914a3330b72378136c2c02d6328a826f6abdad7"}],"title":"ocfs2: validate inline xattrs during inode block validation","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90321","datePublished":"2026-09-17T16:08:38.138Z","dateReserved":"2026-09-11T19:38:34.802Z","dateUpdated":"2026-09-18T17:54:35.231Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:30","lastModifiedDate":"2026-09-18 18:17:53","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90321","Ordinal":"1","Title":"ocfs2: validate inline xattrs during inode block validation","CVE":"CVE-2026-90321","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90321","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate inline xattrs during inode block validation\n\nPatch series \"ocfs2: validate xattr entry bounds\", v7.\n\nThis series validates OCFS2 xattr entry name/value bounds when xattr\nmetadata is read and validated, before getxattr() or listxattr() can walk\nout-of-range entry arrays or offsets from corrupted metadata.\n\n\nThis patch (of 2):\n\nocfs2_validate_inode_block() verifies a dinode before OCFS2 users walk\nmetadata from it, but inline xattr metadata is still checked only in\noperation-specific consumers.  The existing ibody lookup helper validates\ninline header placement and entry count, but inode block validation does\nnot reject entry name/value bounds.\n\nAdd a flat xattr entry validator and call it from inode block validation\nfor inline xattrs.  Keep the operation paths on their existing\nheader/count lookup checks; the full entry bounds check now runs when the\ninode block is validated at read time.\n\nReject corrupted inline xattr metadata before ocfs2_xattr_ibody_get() or\nlistxattr() can walk past the inline storage.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in ocfs2_xattr_find_entry+0x5a/0x170\nRead of size 2 at addr ffff8881242a2000 by task python3/529\nCall Trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  kasan_report+0xe0/0x110\n  ocfs2_xattr_find_entry+0x5a/0x170\n  ocfs2_xattr_get_nolock+0x20a/0x820\n  ocfs2_xattr_get+0x10c/0x1e0\n  __vfs_getxattr+0xe2/0x130\n  vfs_getxattr+0x185/0x1b0","Type":"Description","Title":"ocfs2: validate inline xattrs during inode block validation"}]}}}