SB20260918358 - Use-after-free in Linux kernel ocfs2



SB20260918358 - Use-after-free in Linux kernel ocfs2

Published: September 18, 2026

Security Bulletin ID SB20260918358
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use-after-free (CVE-ID: CVE-2026-90320)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of external extended attribute entry bounds in OCFS2 extended attribute metadata handling when listxattr() or getxattr() processes corrupted external xattr metadata. A local user can invoke listxattr() or getxattr() on a filesystem containing corrupted external xattr metadata to cause a denial of service.

The issue affects both non-indexed external extended attribute blocks and indexed extended attribute buckets.


Remediation

Install update from vendor's website.