{"id":"CVE-2026-89490","summary":"ocfs2: fix readdir position truncation on 32-bit kernels","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix readdir position truncation on 32-bit kernels\n\nIn ocfs2_dir_foreach_blk_el(), the directory cookie position is\nrebuilt with\n\n\tctx-\u003epos = (ctx-\u003epos & ~(sb-\u003es_blocksize - 1)) | offset;\n\n`ctx-\u003epos` is loff_t (signed 64-bit), while `sb-\u003es_blocksize` is\nunsigned long.  On 32-bit kernels unsigned long is 32-bit, so the mask\n\n\t~(sb-\u003es_blocksize - 1)\n\nis computed as a 32-bit unsigned value (e.g. 0xfffff000 for a 4 KiB\nblock size).  In the AND expression with the 64-bit `ctx-\u003epos`, that\nunsigned operand is zero-extended to 64 bits per the usual arithmetic\nconversions, yielding 0x00000000fffff000.  The high 32 bits of\n`ctx-\u003epos` are silently cleared, even though directory size is\nallowed to exceed 4 GiB.\n\nWhen readdir() crosses the 4 GiB boundary on a 32-bit kernel the\nposition is reset back into the first 4 GiB block, making the\nre-validation path re-enumerate already-returned dirents indefinitely.\n\nThis is ocfs2_dir_foreach_blk_el(), the extent-list readdir path taken\nfor all non-inline directories, so a directory large enough to cross\n4 GiB reaches it.\n\nThis is the same class of bug that commit 3dce5bb82c97 (\"exfat: Fix\nbitwise operation having different size\") fixed in exfat, and the\nfix mirrors the equivalent ext4 fix in this series.  Cast the operand\nto loff_t so the mask is 64-bit before the AND:\n\n\tctx-\u003epos = (ctx-\u003epos & ~((loff_t)sb-\u003es_blocksize - 1)) | offset;\n\n64-bit kernels are unaffected.","modified":"2026-09-13T03:47:18.430361695Z","published":"2026-09-11T19:43:42.808Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89490.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1001fb3b69a11eaa0dc7c7428f6edfa48b88997a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a63308ab426f3a3c7e33b02c150ea59054620261"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b53e2b271eeb6040c2a4a78230c570dc41cdcfa4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c0c165487a2ea5a37ddcdab4259157b7a527129c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89490.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89490"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ccd979bdbce9fba8412beb3f1de68a9d0171b12c"},{"fixed":"1001fb3b69a11eaa0dc7c7428f6edfa48b88997a"},{"fixed":"c0c165487a2ea5a37ddcdab4259157b7a527129c"},{"fixed":"b53e2b271eeb6040c2a4a78230c570dc41cdcfa4"},{"fixed":"a63308ab426f3a3c7e33b02c150ea59054620261"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89490.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.16"},{"fixed":"6.12.109"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89490.json"}}],"schema_version":"1.9.0"}