Incorrect Conversion between Numeric Types in Linux kernel - CVE-2026-89490
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service by triggering indefinite directory re-enumeration.
The vulnerability exists due to an incorrect integer conversion in ocfs2_dir_foreach_blk_el() when reading a non-inline directory that crosses the 4 GiB boundary on a 32-bit kernel. A local user can invoke readdir() on an affected directory to cause a denial of service by triggering indefinite directory re-enumeration.
64-bit kernels are unaffected.