{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ocfs2: validate orphan slot during inode read  Patch series \"ocfs2: validate active orphan slots during inode read\".  OCFS2 trusts active ordinary and append-DIO orphan slots read from dinodes. A corrupted slot can therefore index osb_orphan_wipes or the slot-local system-inode cache outside their allocations before the corruption is reported.  Patch 1 validates the ordinary orphan slot used by inode wipe processing. Patch 2 validates the append-DIO orphan slot used by DIO completion and orphan recovery.  Both checks reject corrupt metadata at the existing inode validation boundary.   This patch (of 2):  [BUG] A corrupted dinode with OCFS2_ORPHANED_FL can carry an i_orphaned_slot outside the mounted filesystem slot range. ocfs2_wipe_inode() uses it to index osb_orphan_wipes before looking up the orphan directory, causing an out-of-bounds memory access.  BUG: KASAN: slab-use-after-free in ocfs2_get_system_file_inode+0x780/0x820 fs/ocfs2/sysfile.c:102 Read of size 8 at addr ffff88800b767c00 by task kworker/u8:3/85 Call Trace:  ...  ocfs2_get_system_file_inode+0x780/0x820 fs/ocfs2/sysfile.c:102  ocfs2_wipe_inode+0x292/0xf70 fs/ocfs2/inode.c:840  ocfs2_delete_inode fs/ocfs2/inode.c:1155 [inline]  ocfs2_evict_inode+0x6c9/0x1170 fs/ocfs2/inode.c:1295  evict+0x38e/0x8f0 fs/inode.c:810  iput_final fs/inode.c:1914 [inline]  iput fs/inode.c:1966 [inline]  iput+0x55b/0x8b0 fs/inode.c:1926  ocfs2_recover_orphans+0x610/0xe40 fs/ocfs2/journal.c:2374  ocfs2_complete_recovery+0x5af/0xd00 fs/ocfs2/journal.c:1373  ...  [CAUSE] ocfs2_validate_inode_block() validates i_suballoc_slot but leaves the active ordinary orphan slot unchecked. Downstream consumers assume that the value is smaller than osb-\u003emax_slots.  [FIX] Reject an active i_orphaned_slot outside the slot range during dinode validation, before the inode reaches orphan wipe processing.",
  "id": "DEBIAN-CVE-2026-90205",
  "modified": "2026-09-19T22:47:35.577087334Z",
  "published": "2026-09-17T17:17:15.573Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90205"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-90205"
  ]
}