---
id: CVE-2026-31449
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ext4: validate p_idx bounds in ext4_ext_correct_indexes

  ext4_ext_correct_indexes() walks up the extent tree correcting
  index entries when the first extent in a leaf is…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ext4: validate p_idx bounds in ext4_ext_correct_indexes

  ext4_ext_correct_indexes() walks up the extent tree correcting
  index entries when the first extent in a leaf is…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.19.1, < 6.12.80'
  - 'linux_kernel >= 6.13, < 6.18.21'
  - 'linux_kernel >= 6.19, < 6.19.11'
  - linux_kernel = 2.6.19
  - linux_kernel = 7.0
patched:
  - linux_kernel 6.19.11
published: '2026-04-22'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T09:17:55.763'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-31449'
references:
  - url: 'https://git.kernel.org/stable/c/01bf1e0b997d82c0e353b51ed74ef99698043c33'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/10242e640b36b91ad03d25f3dc77854bbdff8358'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2acb5c12ebd860f30e4faf67e6cc8c44ddfe5fe8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/39d6e2b67651614bac0dc6592fa9836321910067'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/407c944f217c17d4343148011acafebc604d55e1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4d08401aa13f1531216f1a7ae281ca4806e90a5c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/93f2e975ed658ce09db4d4c2877ca2c06540df83'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c5839b34704c9c2f47f079451bdbb22de0da1ed1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-019113.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
  - cve.org
epss: 0.00197
epssPercentile: 0.08323
ingestedAt: '2026-09-08T09:30:09.429Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ext4: validate p_idx bounds in ext4_ext_correct_indexes

ext4_ext_correct_indexes() walks up the extent tree correcting
index entries when the first extent in a leaf is modified. Before
accessing path[k].p_idx->ei_block, there is no validation that
p_idx falls within the valid range of index entries for that
level.

If the on-disk extent header contains a corrupted or crafted
eh_entries value, p_idx can point past the end of the allocated
buffer, causing a slab-out-of-bounds read.

Fix this by validating path[k].p_idx against EXT_LAST_INDEX() at
both access sites: before the while loop and inside it. Return
-EFSCORRUPTED if the index pointer is out of range, consistent
with how other bounds violations are handled in the ext4 extent
tree code.

## Affected

- `linux_kernel >= 2.6.19.1, < 6.12.80`
- `linux_kernel >= 6.13, < 6.18.21`
- `linux_kernel >= 6.19, < 6.19.11`
- `linux_kernel = 2.6.19`
- `linux_kernel = 7.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.11`
