KernelScan.io

CRITICAL Introduced in 3.10

ext4 InlineDir OOB

CVE-2026-89786

CVSS 9.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

KernelScan AI4.4MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_dir() ext4_read_inline_dir() can read a dirent header past the end of its inline buffer, triggering a slab-out-of-bounds read during getdents64(): BUG: KASAN: slab-out-of-bounds in __ext4_check_dir_entry Read of size 2 at addr ffff88800f3dd23c by task exploit/148 ... __ext4_check_dir_entry ext4_read_inline_dir iterate_dir The dirent payload lives in a buffer of exactly inline_size bytes: dir_buf = kmalloc(inline_size, GFP_NOFS); but iteration runs in a position space extra_offset bytes larger (extra_size = extra_offset + inline_size) so the synthetic "." and ".." land at their block-dir offsets. A dirent is formed at "dir_buf + pos - extra_offset", yet the ext4_check_dir_entry() length argument uses the larger extra_size. A position whose dirent header would extend past extra_size is therefore accepted, and the rescan loop's rec_len probe and ext4_check_dir_entry() dereference de->rec_len before the entry is rejected. Reject a position whose minimum-size dirent header would not fit within extra_size before forming de, in both the rescan and main loops, and pass inline_size rather than extra_size to ext4_check_dir_entry() so the length check matches the physical buffer.

02

Engine v0.6.0

Risk summary

A local attacker can trigger a slab-out-of-bounds read in the ext4 inline-data directory reader by calling getdents on a directory whose inline data is in a specific state. The most practical vector is a crafted ext4 filesystem image containing a malformed inline directory, which must be mounted on the target—either via removable media or by a privileged user. The impact is limited to a small information leak from adjacent kernel heap memory.

Affectedfs/ext4/inline.c (ext4)

Vulnerability analysis

When reading an ext4 directory that uses inline data (small directories stored directly in the inode), the iteration code operates in a position space larger than the actual in-memory buffer because synthetic entries for the current and parent directory are placed at their normal block offsets. At positions near the end of this enlarged space, the code forms a directory-entry pointer that extends past the allocated buffer and dereferences the entry's length field before validating that the entry fits within the physical buffer, causing a slab-out-of-bounds read. The fix adds a bounds check before forming the entry pointer in both the rescan and main iteration loops, rejecting positions where even a minimum-size entry header would not fit, and corrects the length argument passed to the entry-validation helper to match the actual buffer size rather than the enlarged position space. The bug is reachable by any local user calling getdents on an ext4 filesystem with the inline_data feature enabled; the most realistic attack vector is a crafted filesystem image containing a malformed inline directory, which requires either physical access to insert removable media or root privileges to mount manually.

03

BranchIntroducedFixed inPatch commit
6.13.106.1.1885fd20d4e50dd
6.63.106.6.1571a1dea633b72
6.123.106.12.110b060861f662d
6.183.106.18.526702c7da86d8
7.23.107.2.636bf17bb90cd
mainline3.107.3-rc19333cc809f0a
5.153.105.15.221d1e7c186555a