CVE-2026-90321

Source
https://cve.org/CVERecord?id=CVE-2026-90321
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90321.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90321
Downstream
Published
2026-09-17T16:08:38Z
Modified
2026-09-18T03:48:37Z
Summary
ocfs2: validate inline xattrs during inode block validation
Details

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate inline xattrs during inode block validation

Patch series "ocfs2: validate xattr entry bounds", v7.

This series validates OCFS2 xattr entry name/value bounds when xattr metadata is read and validated, before getxattr() or listxattr() can walk out-of-range entry arrays or offsets from corrupted metadata.

This patch (of 2):

ocfs2_validate_inode_block() verifies a dinode before OCFS2 users walk metadata from it, but inline xattr metadata is still checked only in operation-specific consumers. The existing ibody lookup helper validates inline header placement and entry count, but inode block validation does not reject entry name/value bounds.

Add a flat xattr entry validator and call it from inode block validation for inline xattrs. Keep the operation paths on their existing header/count lookup checks; the full entry bounds check now runs when the inode block is validated at read time.

Reject corrupted inline xattr metadata before ocfs2_xattr_ibody_get() or listxattr() can walk past the inline storage.

Validation reproduced this kernel report: BUG: KASAN: use-after-free in ocfs2_xattr_find_entry+0x5a/0x170 Read of size 2 at addr ffff8881242a2000 by task python3/529 Call Trace: dump_stack_lvl+0x66/0xa0 print_report+0xce/0x630 kasan_report+0xe0/0x110 ocfs2_xattr_find_entry+0x5a/0x170 ocfs2_xattr_get_nolock+0x20a/0x820 ocfs2_xattr_get+0x10c/0x1e0 __vfs_getxattr+0xe2/0x130 vfs_getxattr+0x185/0x1b0

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90321.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cf1d6c763fbcb115263114302485ad17e7933d87
Fixed
3fd45b24879fa4885b66a582a6e47eda67f11310
Fixed
8914a3330b72378136c2c02d6328a826f6abdad7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90321.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.28
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90321.json"