PT-2026-93393 · Linux · Linux Kernel
CVE-2026-89787
·
Published
2026-09-16
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds read exists in the ext4 file system when handling casefolded encrypted directories. The
ext4 search dir() function performs a pre-check that only verifies if the directory entry name fits within the block boundary, failing to account for the 8-byte hash trailer stored after the name. A crafted entry ending exactly at the block boundary can cause the ext4 match() function to read past the block end. This can lead to a use-after-free condition if the subsequent memory page contains a freed object.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel