-

CVE-2026-89490

ocfs2: fix readdir position truncation on 32-bit kernels

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix readdir position truncation on 32-bit kernels

In ocfs2_dir_foreach_blk_el(), the directory cookie position is
rebuilt with

	ctx->pos = (ctx->pos & ~(sb->s_blocksize - 1)) | offset;

`ctx->pos` is loff_t (signed 64-bit), while `sb->s_blocksize` is
unsigned long.  On 32-bit kernels unsigned long is 32-bit, so the mask

	~(sb->s_blocksize - 1)

is computed as a 32-bit unsigned value (e.g. 0xfffff000 for a 4 KiB
block size).  In the AND expression with the 64-bit `ctx->pos`, that
unsigned operand is zero-extended to 64 bits per the usual arithmetic
conversions, yielding 0x00000000fffff000.  The high 32 bits of
`ctx->pos` are silently cleared, even though directory size is
allowed to exceed 4 GiB.

When readdir() crosses the 4 GiB boundary on a 32-bit kernel the
position is reset back into the first 4 GiB block, making the
re-validation path re-enumerate already-returned dirents indefinitely.

This is ocfs2_dir_foreach_blk_el(), the extent-list readdir path taken
for all non-inline directories, so a directory large enough to cross
4 GiB reaches it.

This is the same class of bug that commit 3dce5bb82c97 ("exfat: Fix
bitwise operation having different size") fixed in exfat, and the
fix mirrors the equivalent ext4 fix in this series.  Cast the operand
to loff_t so the mask is 64-bit before the AND:

	ctx->pos = (ctx->pos & ~((loff_t)sb->s_blocksize - 1)) | offset;

64-bit kernels are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ccd979bdbce9fba8412beb3f1de68a9d0171b12c
Version < c28dc3407937aa8f225942538cd585c9b28ea65a
Status affected
Version ccd979bdbce9fba8412beb3f1de68a9d0171b12c
Version < 94569154ba49f5f85645d2019c8e206213d8404e
Status affected
Version ccd979bdbce9fba8412beb3f1de68a9d0171b12c
Version < 1ae7029823ae4c91664cb32eec7fb8dd5e1a337a
Status affected
Version ccd979bdbce9fba8412beb3f1de68a9d0171b12c
Version < f9dd5cad8d09110ddff2db1fe756aae93c7552ff
Status affected
Version ccd979bdbce9fba8412beb3f1de68a9d0171b12c
Version < 1001fb3b69a11eaa0dc7c7428f6edfa48b88997a
Status affected
Version ccd979bdbce9fba8412beb3f1de68a9d0171b12c
Version < c0c165487a2ea5a37ddcdab4259157b7a527129c
Status affected
Version ccd979bdbce9fba8412beb3f1de68a9d0171b12c
Version < b53e2b271eeb6040c2a4a78230c570dc41cdcfa4
Status affected
Version ccd979bdbce9fba8412beb3f1de68a9d0171b12c
Version < a63308ab426f3a3c7e33b02c150ea59054620261
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.16
Status affected
Version 0
Version < 2.6.16
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1001fb3b69a11eaa0dc7c7428f6edfa48b88997a
https://git.kernel.org/stable/c/c0c165487a2ea5a37ddcdab4259157b7a527129c
https://git.kernel.org/stable/c/b53e2b271eeb6040c2a4a78230c570dc41cdcfa4
https://git.kernel.org/stable/c/a63308ab426f3a3c7e33b02c150ea59054620261
https://git.kernel.org/stable/c/1ae7029823ae4c91664cb32eec7fb8dd5e1a337a
https://git.kernel.org/stable/c/94569154ba49f5f85645d2019c8e206213d8404e
https://git.kernel.org/stable/c/c28dc3407937aa8f225942538cd585c9b28ea65a
https://git.kernel.org/stable/c/f9dd5cad8d09110ddff2db1fe756aae93c7552ff