CVE-2026-89787

Source
https://cve.org/CVERecord?id=CVE-2026-89787
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89787.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89787
Downstream
Published
2026-09-16T08:48:24Z
Modified
2026-09-18T03:48:32Z
Summary
ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()
Details

In the Linux kernel, the following vulnerability has been resolved:

ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()

For casefolded encrypted directories ext4 stores an 8-byte hash trailer after the name (EXT4_DIRENT_HASHES()), at an offset derived from de->name_len. On the sb_no_casefold_compat_fallback() path ext4_match() reads that trailer, but ext4_search_dir()'s by-hand pre-check only tests de->name + de->name_len <= dlimit, which proves the name fits, not the rounded trailer. A crafted entry whose name ends at the block boundary passes the check while EXT4_DIRENT_HASHES(de) lands past the block end, so ext4_match() reads out of bounds on an ordinary lookup. KASAN reports it as a use-after-free when the page after the directory block holds a freed object:

BUG: KASAN: use-after-free in ext4_match (fs/ext4/namei.c:1435) Read of size 4 at addr ffff888010458000 by task exploit Call Trace: ext4_match (fs/ext4/namei.c:1435) ext4_search_dir (fs/ext4/namei.c:1470) __ext4_find_entry (fs/ext4/namei.c:1268 fs/ext4/namei.c:1632) ext4_lookup (fs/ext4/namei.c:1703 fs/ext4/namei.c:1769) ... filename_lookup (fs/namei.c:2842) vfs_statx (fs/stat.c:353) __do_sys_newfstatat (fs/stat.c:538) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)

Require, for hash-in-dirent directories, that the whole entry including the rounded trailer fits before calling ext4_match(). This is the same bound ext4_check_dir_entry() already enforces via ext4_dir_rec_len(), so no well-formed entry is rejected. The other caller, ext4_find_dest_de(), runs ext4_check_dir_entry() first and is unaffected.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89787.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
471fbbea7ff7061b2d6474665cb5a2ceb4fd6500
Fixed
4d20106c536b73c4a8a02652dc85e35898baebf7
Fixed
61a395967de06edba58760e81907a272db749faa
Fixed
e94676a08af6312aa72d8a981232b281f9bcfcf5
Fixed
d8c184bec24b5a00ae96d704856d935eaded1685
Fixed
3933884bc3102898b458c53fbd1ac52eb9cdb8a4
Fixed
83663c0b739480c00cfe785675db87520ec484ed
Fixed
c7e6b863d298f56522d0d08554bbea7f142e6588

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89787.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89787.json"