{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ocfs2: validate inline xattrs during inode block validation  Patch series \"ocfs2: validate xattr entry bounds\", v7.  This series validates OCFS2 xattr entry name/value bounds when xattr metadata is read and validated, before getxattr() or listxattr() can walk out-of-range entry arrays or offsets from corrupted metadata.   This patch (of 2):  ocfs2_validate_inode_block() verifies a dinode before OCFS2 users walk metadata from it, but inline xattr metadata is still checked only in operation-specific consumers.  The existing ibody lookup helper validates inline header placement and entry count, but inode block validation does not reject entry name/value bounds.  Add a flat xattr entry validator and call it from inode block validation for inline xattrs.  Keep the operation paths on their existing header/count lookup checks; the full entry bounds check now runs when the inode block is validated at read time.  Reject corrupted inline xattr metadata before ocfs2_xattr_ibody_get() or listxattr() can walk past the inline storage.  Validation reproduced this kernel report: BUG: KASAN: use-after-free in ocfs2_xattr_find_entry+0x5a/0x170 Read of size 2 at addr ffff8881242a2000 by task python3/529 Call Trace:   dump_stack_lvl+0x66/0xa0   print_report+0xce/0x630   kasan_report+0xe0/0x110   ocfs2_xattr_find_entry+0x5a/0x170   ocfs2_xattr_get_nolock+0x20a/0x820   ocfs2_xattr_get+0x10c/0x1e0   __vfs_getxattr+0xe2/0x130   vfs_getxattr+0x185/0x1b0",
  "id": "DEBIAN-CVE-2026-90321",
  "modified": "2026-09-19T22:47:36.032989589Z",
  "published": "2026-09-17T17:17:30.067Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90321"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-90321"
  ]
}