DEBIAN-CVE-2026-89786
In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4readinlinedir() ext4readinlinedir() can read a dirent header past the end of its inline buffer, triggering a slab-out-of-bounds read during getdents64(): BUG: KASAN: slab-out-of-bounds in _ext4checkdirentry Read of size 2 at addr ffff88800f3dd23c by task exploit/148 ... _ext4checkdirentry ext4readinlinedir iteratedir The dirent payload lives in a buffer of exactly inlinesize bytes: dirbuf = kmalloc(inlinesize, GFPNOFS); but iteration runs in a position space extraoffset bytes larger (extrasize = extraoffset + inlinesize) so the synthetic "." and ".." land at their block-dir offsets. A dirent is formed at "dirbuf + pos - extraoffset", yet the ext4checkdirentry() length argument uses the larger extrasize. A position whose dirent header would extend past extrasize is therefore accepted, and the rescan loop's reclen probe and ext4checkdirentry() dereference de->reclen before the entry is rejected. Reject a position whose minimum-size dirent header would not fit within extrasize before forming de, in both the rescan and main loops, and pass inlinesize rather than extrasize to ext4checkdirentry() so the length check matches the physical buffer.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89786