CVE-2026-92499
In the Linux kernel, the following vulnerability has been resolved:
ext4: validate readdir offset before accessing dirent
A corrupted directory can trigger the following KASAN report when ext4_readdir() resumes from an invalid position:
ext4_dir_llseek() invalidates the directory cookie so that ext4_readdir() rescans directory entries from the start of the block. The rescan checks only the lower bound of rec_len before advancing. A corrupted rec_len can therefore place the offset where the block has insufficient space for a complete directory entry. The rescan itself may dereference that truncated entry, or the main loop may pass it to __ext4_check_dir_entry(). The latter reads de->rec_len before validating the range. For example:
Leer descripción completaMostrar menos
de2 starts at offset 4092 in this 4 KiB block. Its four-byte inode fits in the block, but its rec_len starts at offset 4096 and crosses the boundary.
The minimum safe length is inode-dependent. Encrypted and casefolded directory entries need eight additional hash bytes, while a valid metadata checksum tail is only 12 bytes.
Cache the metadata checksum feature state and derive the minimum directory entry length from the on-disk format. Use it to bound both the rescan and the offset passed to the main loop. Report an offset in a truncated block tail and skip the remainder of the block, while continuing to accept an offset exactly at the block boundary.
Detalles técnicos trazas, registros y código del informe original
BUG: KASAN: use-after-free in __ext4_check_dir_entry+0x5ef/0x820
Read of size 2 at addr ffff88810a646000 by task repro_linear/509
Call Trace:
<TASK>
dump_stack_lvl+0x53/0x70
print_report+0xd0/0x630
kasan_report+0xce/0x100
__ext4_check_dir_entry+0x5ef/0x820
ext4_readdir+0xcde/0x2b70
iterate_dir+0x1a1/0x520
__x64_sys_getdents64+0x12b/0x220
do_syscall_64+0xf9/0x540
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
KASAN reports use-after-free because the out-of-bounds access lands in an
adjacent freed page. The directory buffer itself is still referenced.
block offset 0 4092 4096
|---- de1.rec_len = 4092 -----|----|
de2.inode
| de2.rec_len
^ OOB, reported as UAFCVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-92499",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ac27a0ec112a089f1a5102bc8dffc79c8c815571",
"lessThan": "64d445d40e5ea4c4d4d88880db753b370cb69161",
"versionType": "git"
},
{
"status": "affected",
"version": "ac27a0ec112a089f1a5102bc8dffc79c8c815571",
"lessThan": "b4c728577933753180e3e97f08424d5bcaff705e",
"versionType": "git"
},
{
"status": "affected",
"version": "ac27a0ec112a089f1a5102bc8dffc79c8c815571",
"lessThan": "bc4b7b0414c33b2c8898eb04386df0d21a13dad8",
"versionType": "git"
}
],
"programFiles": [
"fs/ext4/dir.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/ext4/dir.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:52.280",
"references": [
{
"url": "https://git.kernel.org/stable/c/64d445d40e5ea4c4d4d88880db753b370cb69161",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b4c728577933753180e3e97f08424d5bcaff705e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bc4b7b0414c33b2c8898eb04386df0d21a13dad8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate readdir offset before accessing dirent\n\nA corrupted directory can trigger the following KASAN report when\next4_readdir() resumes from an invalid position:\n\n BUG: KASAN: use-after-free in __ext4_check_dir_entry+0x5ef/0x820\n Read of size 2 at addr ffff88810a646000 by task repro_linear/509\n\n Call Trace:\n <TASK>\n dump_stack_lvl+0x53/0x70\n print_report+0xd0/0x630\n kasan_report+0xce/0x100\n __ext4_check_dir_entry+0x5ef/0x820\n ext4_readdir+0xcde/0x2b70\n iterate_dir+0x1a1/0x520\n __x64_sys_getdents64+0x12b/0x220\n do_syscall_64+0xf9/0x540\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n </TASK>\n\nKASAN reports use-after-free because the out-of-bounds access lands in an\nadjacent freed page. The directory buffer itself is still referenced.\n\next4_dir_llseek() invalidates the directory cookie so that ext4_readdir()\nrescans directory entries from the start of the block. The rescan checks\nonly the lower bound of rec_len before advancing. A corrupted rec_len can\ntherefore place the offset where the block has insufficient space for a\ncomplete directory entry. The rescan itself may dereference that truncated\nentry, or the main loop may pass it to __ext4_check_dir_entry(). The latter\nreads de->rec_len before validating the range. For example:\n\n block offset 0 4092 4096\n |---- de1.rec_len = 4092 -----|----|\n de2.inode\n | de2.rec_len\n ^ OOB, reported as UAF\n\nde2 starts at offset 4092 in this 4 KiB block. Its four-byte inode fits in\nthe block, but its rec_len starts at offset 4096 and crosses the boundary.\n\nThe minimum safe length is inode-dependent. Encrypted and casefolded\ndirectory entries need eight additional hash bytes, while a valid metadata\nchecksum tail is only 12 bytes.\n\nCache the metadata checksum feature state and derive the minimum directory\nentry length from the on-disk format. Use it to bound both the rescan and\nthe offset passed to the main loop. Report an offset in a truncated block\ntail and skip the remainder of the block, while continuing to accept an\noffset exactly at the block boundary."
}
],
"lastModified": "2026-09-17T17:17:52.280",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}