Out-of-bounds read in Linux kernel - CVE-2026-89786
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to an out-of-bounds read in ext4_read_inline_dir() when processing inline directory entries during getdents64() calls. A remote attacker can cause the kernel to process an inline directory entry whose header extends beyond the inline buffer to disclose sensitive information and cause a denial of service.
Affected software
How to mitigate CVE-2026-89786
External References
- https://git.kernel.org/stable/c/1a1dea633b724a1c042dbcdb1fed27f410916688
- https://git.kernel.org/stable/c/36bf17bb90cdf7a623499b624b05acde4d2feef5
- https://git.kernel.org/stable/c/5fd20d4e50dd6e460b3ea8e4396f8553d4526f8f
- https://git.kernel.org/stable/c/6702c7da86d8cdb88d0fc57166286e115ffeb8c0
- https://git.kernel.org/stable/c/9333cc809f0a89e001b814155a6cb8903a6274df
- https://git.kernel.org/stable/c/b060861f662d4826dc700a1c3584243bb3474cfe
- https://git.kernel.org/stable/c/d1e7c186555ad65554fd2f2b02f5a539aa35ae48