CVE-2026-31449 (GCVE-0-2026-31449)
Vulnerability from cvelistv5
Published
2026-04-22 13:53
Modified
2026-08-05 12:22
Summary
In the Linux kernel, the following vulnerability has been resolved: ext4: validate p_idx bounds in ext4_ext_correct_indexes ext4_ext_correct_indexes() walks up the extent tree correcting index entries when the first extent in a leaf is modified. Before accessing path[k].p_idx->ei_block, there is no validation that p_idx falls within the valid range of index entries for that level. If the on-disk extent header contains a corrupted or crafted eh_entries value, p_idx can point past the end of the allocated buffer, causing a slab-out-of-bounds read. Fix this by validating path[k].p_idx against EXT_LAST_INDEX() at both access sites: before the while loop and inside it. Return -EFSCORRUPTED if the index pointer is out of range, consistent with how other bounds violations are handled in the ext4 extent tree code.
Impacted products
Vendor Product Version
Linux Linux Version: a86c61812637c7dd0c57e29880cffd477b62f2e7
Version: a86c61812637c7dd0c57e29880cffd477b62f2e7
Version: a86c61812637c7dd0c57e29880cffd477b62f2e7
Version: a86c61812637c7dd0c57e29880cffd477b62f2e7
Version: a86c61812637c7dd0c57e29880cffd477b62f2e7
Version: a86c61812637c7dd0c57e29880cffd477b62f2e7
Version: a86c61812637c7dd0c57e29880cffd477b62f2e7
Version: a86c61812637c7dd0c57e29880cffd477b62f2e7
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/ext4/extents.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "39d6e2b67651614bac0dc6592fa9836321910067",
              "status": "affected",
              "version": "a86c61812637c7dd0c57e29880cffd477b62f2e7",
              "versionType": "git"
            },
            {
              "lessThan": "c5839b34704c9c2f47f079451bdbb22de0da1ed1",
              "status": "affected",
              "version": "a86c61812637c7dd0c57e29880cffd477b62f2e7",
              "versionType": "git"
            },
            {
              "lessThan": "10242e640b36b91ad03d25f3dc77854bbdff8358",
              "status": "affected",
              "version": "a86c61812637c7dd0c57e29880cffd477b62f2e7",
              "versionType": "git"
            },
            {
              "lessThan": "4d08401aa13f1531216f1a7ae281ca4806e90a5c",
              "status": "affected",
              "version": "a86c61812637c7dd0c57e29880cffd477b62f2e7",
              "versionType": "git"
            },
            {
              "lessThan": "407c944f217c17d4343148011acafebc604d55e1",
              "status": "affected",
              "version": "a86c61812637c7dd0c57e29880cffd477b62f2e7",
              "versionType": "git"
            },
            {
              "lessThan": "93f2e975ed658ce09db4d4c2877ca2c06540df83",
              "status": "affected",
              "version": "a86c61812637c7dd0c57e29880cffd477b62f2e7",
              "versionType": "git"
            },
            {
              "lessThan": "01bf1e0b997d82c0e353b51ed74ef99698043c33",
              "status": "affected",
              "version": "a86c61812637c7dd0c57e29880cffd477b62f2e7",
              "versionType": "git"
            },
            {
              "lessThan": "2acb5c12ebd860f30e4faf67e6cc8c44ddfe5fe8",
              "status": "affected",
              "version": "a86c61812637c7dd0c57e29880cffd477b62f2e7",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/ext4/extents.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.19"
            },
            {
              "lessThan": "2.6.19",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.259",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.140",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.80",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.21",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.259",
                  "versionStartIncluding": "2.6.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.210",
                  "versionStartIncluding": "2.6.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.175",
                  "versionStartIncluding": "2.6.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.140",
                  "versionStartIncluding": "2.6.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.80",
                  "versionStartIncluding": "2.6.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.21",
                  "versionStartIncluding": "2.6.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.11",
                  "versionStartIncluding": "2.6.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "2.6.19",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate p_idx bounds in ext4_ext_correct_indexes\n\next4_ext_correct_indexes() walks up the extent tree correcting\nindex entries when the first extent in a leaf is modified. Before\naccessing path[k].p_idx-\u003eei_block, there is no validation that\np_idx falls within the valid range of index entries for that\nlevel.\n\nIf the on-disk extent header contains a corrupted or crafted\neh_entries value, p_idx can point past the end of the allocated\nbuffer, causing a slab-out-of-bounds read.\n\nFix this by validating path[k].p_idx against EXT_LAST_INDEX() at\nboth access sites: before the while loop and inside it. Return\n-EFSCORRUPTED if the index pointer is out of range, consistent\nwith how other bounds violations are handled in the ext4 extent\ntree code."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable ext4 code is reached through local filesystem operations such as pwrite64, fallocate, or truncate on a mounted ext4 filesystem. It is not directly reachable through network packets, and physical access is not strictly required because a crafted filesystem image can be supplied as a local/block-device image.\nAC:L - Once the crafted/corrupted extent metadata is present on a mounted filesystem, the trigger is a straightforward file write or extent update with no race or condition outside the attacker\u0027s control. Syzbot reproduced it through the ordinary buffered-write path.\nPR:N - In the highest-severity defensible scenario, the attacker supplies a malicious ext4 image and relies on a victim/admin or automount workflow to mount it, so the attacker needs no privileges on the target. Ext4 is not user-namespace mountable, but that mount requirement is captured as user interaction rather than attacker privileges.\nUI:R - Exploitation requires the crafted ext4 filesystem to be mounted and then operated on, such as by writing to the crafted file. There is no pre-authentication or autonomous network-facing path into this code.\nS:U - The impact is within the kernel/filesystem security authority of the same host. This is not a guest-to-host escape or another cross-scope boundary violation.\nC:H - The bug is a slab out-of-bounds access from an attacker-controlled extent-tree pointer, which can expose adjacent kernel memory in a corrupted heap layout. Under the required overestimation rule, this memory-corruption primitive supports high confidentiality impact.\nI:H - The unchecked p_idx is used to update ei_block, so an out-of-bounds pointer can corrupt memory or filesystem metadata beyond the valid extent index entry. Such kernel memory corruption is defensibly treated as high integrity impact.\nA:H - The reported failure is a KASAN slab-out-of-bounds fault in kernel ext4 code and can cause an oops/panic or filesystem failure. Repeated triggering through file operations can deny availability of the host or mounted filesystem."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:22:39.911Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/39d6e2b67651614bac0dc6592fa9836321910067"
        },
        {
          "url": "https://git.kernel.org/stable/c/c5839b34704c9c2f47f079451bdbb22de0da1ed1"
        },
        {
          "url": "https://git.kernel.org/stable/c/10242e640b36b91ad03d25f3dc77854bbdff8358"
        },
        {
          "url": "https://git.kernel.org/stable/c/4d08401aa13f1531216f1a7ae281ca4806e90a5c"
        },
        {
          "url": "https://git.kernel.org/stable/c/407c944f217c17d4343148011acafebc604d55e1"
        },
        {
          "url": "https://git.kernel.org/stable/c/93f2e975ed658ce09db4d4c2877ca2c06540df83"
        },
        {
          "url": "https://git.kernel.org/stable/c/01bf1e0b997d82c0e353b51ed74ef99698043c33"
        },
        {
          "url": "https://git.kernel.org/stable/c/2acb5c12ebd860f30e4faf67e6cc8c44ddfe5fe8"
        }
      ],
      "title": "ext4: validate p_idx bounds in ext4_ext_correct_indexes",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-31449",
    "datePublished": "2026-04-22T13:53:44.777Z",
    "dateReserved": "2026-03-09T15:48:24.091Z",
    "dateUpdated": "2026-08-05T12:22:39.911Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…