SB20260918358 - Use-after-free in Linux kernel ocfs2
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-90320)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of external extended attribute entry bounds in OCFS2 extended attribute metadata handling when listxattr() or getxattr() processes corrupted external xattr metadata. A local user can invoke listxattr() or getxattr() on a filesystem containing corrupted external xattr metadata to cause a denial of service.
The issue affects both non-indexed external extended attribute blocks and indexed extended attribute buckets.
Remediation
Install update from vendor's website.