CVE-2026-89490

Source
https://cve.org/CVERecord?id=CVE-2026-89490
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89490.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89490
Downstream
Published
2026-09-11T19:43:42Z
Modified
2026-09-13T03:47:18Z
Summary
ocfs2: fix readdir position truncation on 32-bit kernels
Details

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix readdir position truncation on 32-bit kernels

In ocfs2_dir_foreach_blk_el(), the directory cookie position is rebuilt with

ctx->pos = (ctx->pos & ~(sb->s_blocksize - 1)) | offset;

ctx->pos is loff_t (signed 64-bit), while sb->s_blocksize is unsigned long. On 32-bit kernels unsigned long is 32-bit, so the mask

~(sb->s_blocksize - 1)

is computed as a 32-bit unsigned value (e.g. 0xfffff000 for a 4 KiB block size). In the AND expression with the 64-bit ctx->pos, that unsigned operand is zero-extended to 64 bits per the usual arithmetic conversions, yielding 0x00000000fffff000. The high 32 bits of ctx->pos are silently cleared, even though directory size is allowed to exceed 4 GiB.

When readdir() crosses the 4 GiB boundary on a 32-bit kernel the position is reset back into the first 4 GiB block, making the re-validation path re-enumerate already-returned dirents indefinitely.

This is ocfs2_dir_foreach_blk_el(), the extent-list readdir path taken for all non-inline directories, so a directory large enough to cross 4 GiB reaches it.

This is the same class of bug that commit 3dce5bb82c97 ("exfat: Fix bitwise operation having different size") fixed in exfat, and the fix mirrors the equivalent ext4 fix in this series. Cast the operand to loff_t so the mask is 64-bit before the AND:

ctx->pos = (ctx->pos & ~((loff_t)sb->s_blocksize - 1)) | offset;

64-bit kernels are unaffected.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89490.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ccd979bdbce9fba8412beb3f1de68a9d0171b12c
Fixed
1001fb3b69a11eaa0dc7c7428f6edfa48b88997a
Fixed
c0c165487a2ea5a37ddcdab4259157b7a527129c
Fixed
b53e2b271eeb6040c2a4a78230c570dc41cdcfa4
Fixed
a63308ab426f3a3c7e33b02c150ea59054620261

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89490.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.16
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89490.json"