Out-of-bounds read in Linux kernel - CVE-2026-89492
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to read memory beyond the bounds of a directory-index metadata block.
The vulnerability exists due to an out-of-bounds read in the OCFS2 directory index entry-list validation when processing a crafted on-disk image. A local user can supply a crafted image and access an indexed directory to read beyond the entry array.
Exploitation is reachable through path lookup, stat(), or open() operations after the image is mounted.