« Volver al listado

CVE-2026-89787

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()

For casefolded encrypted directories ext4 stores an 8-byte hash trailer after the name (EXT4_DIRENT_HASHES()), at an offset derived from de->name_len. On the sb_no_casefold_compat_fallback() path ext4_match() reads that trailer, but ext4_search_dir()'s by-hand pre-check only tests de->name + de->name_len <= dlimit, which proves the name fits, not the rounded trailer.

Leer descripción completaMostrar menos

A crafted entry whose name ends at the block boundary passes the check while EXT4_DIRENT_HASHES(de) lands past the block end, so ext4_match() reads out of bounds on an ordinary lookup. KASAN reports it as a use-after-free when the page after the directory block holds a freed object:

Require, for hash-in-dirent directories, that the whole entry including the rounded trailer fits before calling ext4_match(). This is the same bound ext4_check_dir_entry() already enforces via ext4_dir_rec_len(), so no well-formed entry is rejected. The other caller, ext4_find_dest_de(), runs ext4_check_dir_entry() first and is unaffected.

Detalles técnicos trazas, registros y código del informe original
  BUG: KASAN: use-after-free in ext4_match (fs/ext4/namei.c:1435)
  Read of size 4 at addr ffff888010458000 by task exploit
  Call Trace:
   ext4_match (fs/ext4/namei.c:1435)
   ext4_search_dir (fs/ext4/namei.c:1470)
   __ext4_find_entry (fs/ext4/namei.c:1268 fs/ext4/namei.c:1632)
   ext4_lookup (fs/ext4/namei.c:1703 fs/ext4/namei.c:1769)
   ...
   filename_lookup (fs/namei.c:2842)
   vfs_statx (fs/stat.c:353)
   __do_sys_newfstatat (fs/stat.c:538)
   do_syscall_64 (arch/x86/entry/syscall_64.c:94)
   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89787",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "471fbbea7ff7061b2d6474665cb5a2ceb4fd6500",
              "lessThan": "4d20106c536b73c4a8a02652dc85e35898baebf7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "471fbbea7ff7061b2d6474665cb5a2ceb4fd6500",
              "lessThan": "61a395967de06edba58760e81907a272db749faa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "471fbbea7ff7061b2d6474665cb5a2ceb4fd6500",
              "lessThan": "e94676a08af6312aa72d8a981232b281f9bcfcf5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "471fbbea7ff7061b2d6474665cb5a2ceb4fd6500",
              "lessThan": "d8c184bec24b5a00ae96d704856d935eaded1685",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "471fbbea7ff7061b2d6474665cb5a2ceb4fd6500",
              "lessThan": "3933884bc3102898b458c53fbd1ac52eb9cdb8a4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "471fbbea7ff7061b2d6474665cb5a2ceb4fd6500",
              "lessThan": "83663c0b739480c00cfe785675db87520ec484ed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "471fbbea7ff7061b2d6474665cb5a2ceb4fd6500",
              "lessThan": "c7e6b863d298f56522d0d08554bbea7f142e6588",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/ext4/namei.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/ext4/namei.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T09:17:09.460",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3933884bc3102898b458c53fbd1ac52eb9cdb8a4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4d20106c536b73c4a8a02652dc85e35898baebf7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/61a395967de06edba58760e81907a272db749faa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/83663c0b739480c00cfe785675db87520ec484ed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c7e6b863d298f56522d0d08554bbea7f142e6588",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d8c184bec24b5a00ae96d704856d935eaded1685",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e94676a08af6312aa72d8a981232b281f9bcfcf5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: check dir entry fits before reading the hash trailer in ext4_search_dir()\n\nFor casefolded encrypted directories ext4 stores an 8-byte hash trailer\nafter the name (EXT4_DIRENT_HASHES()), at an offset derived from\nde->name_len.  On the sb_no_casefold_compat_fallback() path ext4_match()\nreads that trailer, but ext4_search_dir()'s by-hand pre-check only tests\nde->name + de->name_len <= dlimit, which proves the name fits, not the\nrounded trailer.  A crafted entry whose name ends at the block boundary\npasses the check while EXT4_DIRENT_HASHES(de) lands past the block end,\nso ext4_match() reads out of bounds on an ordinary lookup.  KASAN reports\nit as a use-after-free when the page after the directory block holds a\nfreed object:\n\n  BUG: KASAN: use-after-free in ext4_match (fs/ext4/namei.c:1435)\n  Read of size 4 at addr ffff888010458000 by task exploit\n  Call Trace:\n   ext4_match (fs/ext4/namei.c:1435)\n   ext4_search_dir (fs/ext4/namei.c:1470)\n   __ext4_find_entry (fs/ext4/namei.c:1268 fs/ext4/namei.c:1632)\n   ext4_lookup (fs/ext4/namei.c:1703 fs/ext4/namei.c:1769)\n   ...\n   filename_lookup (fs/namei.c:2842)\n   vfs_statx (fs/stat.c:353)\n   __do_sys_newfstatat (fs/stat.c:538)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nRequire, for hash-in-dirent directories, that the whole entry including\nthe rounded trailer fits before calling ext4_match().  This is the same\nbound ext4_check_dir_entry() already enforces via ext4_dir_rec_len(), so\nno well-formed entry is rejected.  The other caller, ext4_find_dest_de(),\nruns ext4_check_dir_entry() first and is unaffected."
    }
  ],
  "lastModified": "2026-09-16T09:17:09.460",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}