Junglewise Threat Intelligence

CVE-2026-31449: Linux Kernel ext4 out-of-bounds read in ext4_ext_correct_indexes

CVE-2026-31449 · Severity: high · CVSS 7.8 · Published 2026-04-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's ext4 file system, which is responsible for managing how data is stored on disks. By using a specially crafted or corrupted disk image, an attacker could cause the system to crash or potentially access sensitive information. This issue primarily affects systems where untrusted storage media can be mounted or where disk images are processed.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ext4_ext_correct_indexes() function within the Linux kernel's ext4 file system implementation. The root cause is a lack of bounds validation for the p_idx pointer before it is used to access index entries while walking the extent tree. If a disk contains a corrupted or maliciously crafted extent header with an invalid eh_entries value, the pointer can point beyond the allocated buffer, leading to a slab-out-of-bounds read. This can be triggered during file system operations that modify the first extent in a leaf. The vulnerability is reachable locally, typically requiring a user to mount a crafted filesystem or interact with a malicious disk image. Patches have been released across multiple stable kernel branches to validate p_idx against EXT_LAST_INDEX().

Affected products

  • Linux Linux Kernel 2.6.19.1 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11, 7.0-rc1 to 7.0-rc5

Timeline

  • 2026-03-03: other: Vulnerability reported by syzbot
  • 2026-04-22: disclosed
  • 2026-04-22: advisory
  • 2026-05-17: patched

References

Related threats