PT-2026-94669 · Linux · Linux Kernel

CVE-2026-90321

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the OCFS2 file system where inline extended attribute (xattr) metadata is not fully validated during inode block validation. Specifically, the ocfs2 validate inode block() function fails to reject invalid entry name and value bounds. This allows corrupted metadata to cause getxattr() or listxattr() to access out-of-range entry arrays or offsets, potentially leading to a use-after-free condition in the ocfs2 xattr find entry() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102530
CVE-2026-90321
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel