SB20260917175 - Out-of-bounds read in Linux kernel ext4
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-89786)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to an out-of-bounds read in ext4_read_inline_dir() when processing inline directory entries during getdents64() calls. A remote attacker can cause the kernel to process an inline directory entry whose header extends beyond the inline buffer to disclose sensitive information and cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1a1dea633b724a1c042dbcdb1fed27f410916688
- https://git.kernel.org/stable/c/36bf17bb90cdf7a623499b624b05acde4d2feef5
- https://git.kernel.org/stable/c/5fd20d4e50dd6e460b3ea8e4396f8553d4526f8f
- https://git.kernel.org/stable/c/6702c7da86d8cdb88d0fc57166286e115ffeb8c0
- https://git.kernel.org/stable/c/9333cc809f0a89e001b814155a6cb8903a6274df
- https://git.kernel.org/stable/c/b060861f662d4826dc700a1c3584243bb3474cfe
- https://git.kernel.org/stable/c/d1e7c186555ad65554fd2f2b02f5a539aa35ae48