---
id: CVE-2026-90320
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ocfs2: validate external xattr entries when reading metadata

  ocfs2_validate_xattr_block() checks the xattr block header before the
  block reaches higher-level xattr use…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ocfs2: validate external xattr entries when reading metadata

  ocfs2_validate_xattr_block() checks the xattr block header before the
  block reaches higher-level xattr use…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= cf1d6c763fbcb115263114302485ad17e7933d87 <
    9f4129b6905b7d638bbc9eb8013c3989cbe30b7e
  - >-
    Linux >= cf1d6c763fbcb115263114302485ad17e7933d87 <
    2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6
  - Linux 2.6.28
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:53.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90320'
references:
  - url: 'https://git.kernel.org/stable/c/2cf82b46d5e43be0dfbaac7fa1073cec2fc1f5e6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9f4129b6905b7d638bbc9eb8013c3989cbe30b7e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00174
epssPercentile: 0.05991
ingestedAt: '2026-09-17T16:21:47.823Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate external xattr entries when reading metadata

ocfs2_validate_xattr_block() checks the xattr block header before the
block reaches higher-level xattr users, but it does not verify that a
non-indexed block's xh_count and entry offsets fit inside the block. 
Indexed buckets likewise reach list/get consumers after ECC without an
entry-bounds check.

Use the flat xattr entry validator for non-indexed external xattr blocks,
and use a bucket-specific validator for indexed buckets at metadata read
time.  The bucket validator keeps the entry array bounded by the first
bucket block while checking name/value offsets against the bucket block
they target.

Reject corrupted external xattr metadata before listxattr() or getxattr()
can walk out-of-range entry arrays or name/value offsets.

Validation reproduced this kernel report:
BUG: KASAN: use-after-free in ocfs2_xattr_list_entries+0xd7/0x190
Read of size 1 at addr ffff88810a654007 by task ocfs2_xattr_lis/630
Call Trace:
  dump_stack_lvl+0x66/0xa0
  print_report+0xce/0x630
  kasan_report+0xe0/0x110
  ocfs2_xattr_list_entries+0xd7/0x190
  ocfs2_listxattr+0x3f6/0x610
  listxattr+0x90/0xe0
  path_listxattrat+0xed/0x220
  do_syscall_64+0x115/0x6a0
  entry_SYSCALL_64_after_hwframe+0x77/0x7f

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
