Out-of-bounds read in Linux kernel - CVE-2026-90321
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to trigger an out-of-bounds read.
The vulnerability exists due to insufficient bounds checking in OCFS2 inline extended-attribute metadata when accessing an inode with corrupted inline extended attributes. A local user can invoke getxattr() or listxattr() on the affected inode to trigger an out-of-bounds read.