ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()
Published Sep 16, 2026
No CVSS score
EPSS 0.21%
Description
For casefolded encrypted directories ext4 stores an 8-byte hash trailer after the name (EXT4_DIRENT_HASHES()), at an offset derived from de->name_len. On the sb_no_casefold_compat_fallback() path ext4_match() reads that trailer, but ext4_search_dir()'s by-hand pre-check only tests de->name + de->name_len <= dlimit, which proves the name fits, not the rounded trailer. A crafted entry whose name ends at the block boundary passes the check while EXT4_DIRENT_HASHES(de) lands past the block end, so ext4_match() reads out of bounds on an ordinary lookup. KASAN reports it as a use-after-free when the page after the directory block holds a freed object:
BUG: KASAN: use-after-free in ext4_match (fs/ext4/namei.c:1435) Read of size 4 at addr ffff888010458000 by task exploit Call Trace: ext4_match (fs/ext4/namei.c:1435) ext4_search_dir (fs/ext4/namei.c:1470) __ext4_find_entry (fs/ext4/namei.c:1268 fs/ext4/namei.c:1632) ext4_lookup (fs/ext4/namei.c:1703 fs/ext4/namei.c:1769) ... filename_lookup (fs/namei.c:2842) vfs_statx (fs/stat.c:353) __do_sys_newfstatat (fs/stat.c:538) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Require, for hash-in-dirent directories, that the whole entry including the rounded trailer fits before calling ext4_match(). This is the same bound ext4_check_dir_entry() already enforces via ext4_dir_rec_len(), so no well-formed entry is rejected. The other caller, ext4_find_dest_de(), runs ext4_check_dir_entry() first and is unaffected.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.13
Unaffected
- ≥ 0, < 5.13
- ≥ 5.15.221, ≤ 5.15.*
- ≥ 6.1.188, ≤ 6.1.*
- ≥ 6.12.110, ≤ 6.12.*
- ≥ 6.18.52, ≤ 6.18.*
- ≥ 6.6.157, ≤ 6.6.*
- ≥ 7.2.6, ≤ 7.2.*
- 7.3-rc1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-80308 Advisory
- https://git.kernel.org/stable/c/3933884bc3102898b458c53fbd1ac52eb9cdb8a4
- https://git.kernel.org/stable/c/4d20106c536b73c4a8a02652dc85e35898baebf7
- https://git.kernel.org/stable/c/61a395967de06edba58760e81907a272db749faa
- https://git.kernel.org/stable/c/83663c0b739480c00cfe785675db87520ec484ed
- https://git.kernel.org/stable/c/c7e6b863d298f56522d0d08554bbea7f142e6588
- https://git.kernel.org/stable/c/d8c184bec24b5a00ae96d704856d935eaded1685
- https://git.kernel.org/stable/c/e94676a08af6312aa72d8a981232b281f9bcfcf5
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data