Junglewise Threat Intelligence

CVE-2026-90204: Linux kernel OCFS2 use-after-free in DIO orphan slot validation

CVE-2026-90204 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The OCFS2 filesystem driver in the Linux kernel did not validate inode metadata fields when reading file structures from disk. A maliciously crafted or corrupted OCFS2 filesystem could trigger a use-after-free memory error during file deletion operations, potentially leading to kernel crash or arbitrary code execution on affected systems.

Technical details

The vulnerability is a use-after-free bug in the OCFS2 filesystem's DIO (Direct I/O) orphan slot handling. The root cause is that the dinode validator (ocfs2_validate_inode_block) did not check whether the i_dio_orphaned_slot field falls within the valid filesystem slot range before allowing the inode to be loaded into memory. When an inode with an out-of-range slot value is accessed during orphan recovery, ocfs2_del_inode_from_orphan() dereferences an invalid cache pointer, triggering a KASAN slab-use-after-free error. The attack requires a malformed OCFS2 filesystem image (corrupted dinode at offset 0xa1), which can be supplied as a mounted volume. The fix adds validation in ocfs2_validate_inode_block to reject dinodes with OCFS2_DIO_ORPHANED_FL flag set if i_dio_orphaned_slot exceeds max_slots.

Affected products

  • Linux Linux kernel multiple versions through 6.9 and 7.x

Timeline

  • 2026-08-03: other: Patch submitted by ZhengYuan Huang
  • 2026-08-13: patched: Merged upstream in commit bb88131c9831075b8dc08cdd375743e5d44c7ca2
  • 2026-09-14: patched: Backported to stable kernel branches via commit 418e0ae42fa769d354b15e62c01a00413024755b
  • 2026-09-17: disclosed

References

Related threats