Executive brief
A vulnerability in the Linux kernel's directory caching system could allow a system administrator to trigger a kernel crash or potentially access restricted memory. By configuring a specific system parameter (dhash_entries) to an unusually low value, the kernel miscalculates memory offsets, leading to an out-of-bounds memory access. This could result in a complete system failure (Blue Screen/Kernel Panic) or unauthorized access to sensitive kernel data.
Technical details
An out-of-bounds (OOB) read exists in the Linux kernel's dentry_hashtable implementation within fs/dcache.c. When the boot parameter 'dhash_entries' is set to 1, dcache_init() calculates a d_hash_shift value of 32. During a dentry lookup via __d_lookup, the kernel performs a right-shift operation on a 32-bit hash value by the d_hash_shift amount. Under C standards, shifting a 32-bit value by 32 bits is undefined behavior; in this implementation, it results in an incorrect index that points to unallocated memory. An attacker with sufficient privileges to modify kernel boot parameters can trigger this OOB read to cause a kernel oops/denial of service or potentially leak kernel memory. The fix involves enforcing a minimum of two buckets in the dentry_hashtable to ensure d_hash_shift remains within safe bounds.
Affected products
- Linux Linux Kernel All versions prior to the April 2026 patches
Timeline
- 2026-01-30: other: Patch submitted by developer
- 2026-04-22: patched: Commits merged into various stable branches by Greg Kroah-Hartman
- 2026-05-05: disclosed: CVE published
References
- https://git.kernel.org/stable/c/277cedabb0ab86baae83fa58218be13c6d3e5526
- https://git.kernel.org/stable/c/426ef05e82ee52c8d0e95fc0808b7383d8352d73
- https://git.kernel.org/stable/c/5718df131ab78897a9dd1f2e71c3ba732d4392af
- https://git.kernel.org/stable/c/755b40903eff563768d4d96fd4ef51ec48adde3b
- https://git.kernel.org/stable/c/ddd57ebce245f9c7e2f6902a6c087d6186d2385d
- https://git.kernel.org/stable/c/f08fe8891c3eeb63b73f9f1f6d97aa629c821579