---
id: CVE-2026-90321
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ocfs2: validate inline xattrs during inode block validation

  Patch series "ocfs2: validate xattr entry bounds", v7.

  This series validates OCFS2 xattr entry name/value …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ocfs2: validate inline xattrs during inode block validation

  Patch series "ocfs2: validate xattr entry bounds", v7.

  This series validates OCFS2 xattr entry name/value …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= cf1d6c763fbcb115263114302485ad17e7933d87 <
    3fd45b24879fa4885b66a582a6e47eda67f11310
  - >-
    Linux >= cf1d6c763fbcb115263114302485ad17e7933d87 <
    8914a3330b72378136c2c02d6328a826f6abdad7
  - Linux 2.6.28
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:53.710'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90321'
references:
  - url: 'https://git.kernel.org/stable/c/3fd45b24879fa4885b66a582a6e47eda67f11310'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8914a3330b72378136c2c02d6328a826f6abdad7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00174
epssPercentile: 0.0604
ingestedAt: '2026-09-17T16:21:47.823Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate inline xattrs during inode block validation

Patch series "ocfs2: validate xattr entry bounds", v7.

This series validates OCFS2 xattr entry name/value bounds when xattr
metadata is read and validated, before getxattr() or listxattr() can walk
out-of-range entry arrays or offsets from corrupted metadata.


This patch (of 2):

ocfs2_validate_inode_block() verifies a dinode before OCFS2 users walk
metadata from it, but inline xattr metadata is still checked only in
operation-specific consumers.  The existing ibody lookup helper validates
inline header placement and entry count, but inode block validation does
not reject entry name/value bounds.

Add a flat xattr entry validator and call it from inode block validation
for inline xattrs.  Keep the operation paths on their existing
header/count lookup checks; the full entry bounds check now runs when the
inode block is validated at read time.

Reject corrupted inline xattr metadata before ocfs2_xattr_ibody_get() or
listxattr() can walk past the inline storage.

Validation reproduced this kernel report:
BUG: KASAN: use-after-free in ocfs2_xattr_find_entry+0x5a/0x170
Read of size 2 at addr ffff8881242a2000 by task python3/529
Call Trace:
  dump_stack_lvl+0x66/0xa0
  print_report+0xce/0x630
  kasan_report+0xe0/0x110
  ocfs2_xattr_find_entry+0x5a/0x170
  ocfs2_xattr_get_nolock+0x20a/0x820
  ocfs2_xattr_get+0x10c/0x1e0
  __vfs_getxattr+0xe2/0x130
  vfs_getxattr+0x185/0x1b0

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
