PT-2026-93393 · Linux · Linux Kernel

CVE-2026-89787

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds read exists in the ext4 file system when handling casefolded encrypted directories. The ext4 search dir() function performs a pre-check that only verifies if the directory entry name fits within the block boundary, failing to account for the 8-byte hash trailer stored after the name. A crafted entry ending exactly at the block boundary can cause the ext4 match() function to read past the block end. This can lead to a use-after-free condition if the subsequent memory page contains a freed object.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101439
CVE-2026-89787
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel