{"cvss":7.8,"datePublished":"2026-04-22T14:16:38.933","dateUpdated":"2026-09-08T09:17:55.763","description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate p_idx bounds in ext4_ext_correct_indexes\n\next4_ext_correct_indexes() walks up the extent tree correcting\nindex entries when the first extent in a leaf is modified. Before\naccessing path[k].p_idx->ei_block, there is no validation that\np_idx falls within the valid range of index entries for that\nlevel.\n\nIf the on-disk extent header contains a corrupted or crafted\neh_entries value, p_idx can point past the end of the allocated\nbuffer, causing a slab-out-of-bounds read.\n\nFix this by validating path[k].p_idx against EXT_LAST_INDEX() at\nboth access sites: before the while loop and inside it. Return\n-EFSCORRUPTED if the index pointer is out of range, consistent\nwith how other bounds violations are handled in the ext4 extent\ntree code.","id":"CVE-2026-31449","raw":{"affected":[{"affectedData":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/ext4/extents.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"39d6e2b67651614bac0dc6592fa9836321910067","status":"affected","version":"a86c61812637c7dd0c57e29880cffd477b62f2e7","versionType":"git"},{"lessThan":"c5839b34704c9c2f47f079451bdbb22de0da1ed1","status":"affected","version":"a86c61812637c7dd0c57e29880cffd477b62f2e7","versionType":"git"},{"lessThan":"10242e640b36b91ad03d25f3dc77854bbdff8358","status":"affected","version":"a86c61812637c7dd0c57e29880cffd477b62f2e7","versionType":"git"},{"lessThan":"4d08401aa13f1531216f1a7ae281ca4806e90a5c","status":"affected","version":"a86c61812637c7dd0c57e29880cffd477b62f2e7","versionType":"git"},{"lessThan":"407c944f217c17d4343148011acafebc604d55e1","status":"affected","version":"a86c61812637c7dd0c57e29880cffd477b62f2e7","versionType":"git"},{"lessThan":"93f2e975ed658ce09db4d4c2877ca2c06540df83","status":"affected","version":"a86c61812637c7dd0c57e29880cffd477b62f2e7","versionType":"git"},{"lessThan":"01bf1e0b997d82c0e353b51ed74ef99698043c33","status":"affected","version":"a86c61812637c7dd0c57e29880cffd477b62f2e7","versionType":"git"},{"lessThan":"2acb5c12ebd860f30e4faf67e6cc8c44ddfe5fe8","status":"affected","version":"a86c61812637c7dd0c57e29880cffd477b62f2e7","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/ext4/extents.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.19"},{"lessThan":"2.6.19","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.259","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.210","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.175","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.140","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.80","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.21","versionType":"semver"},{"lessThanOrEqual":"6.19.*","status":"unaffected","version":"6.19.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.0","versionType":"original_commit_for_fix"}]}],"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"affectedData":[{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]}],"source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"6126AEF2-0176-48D1-96AD-72781F726931","versionEndExcluding":"6.12.80","versionStartIncluding":"2.6.19.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"ED39847A-3B46-4729-B7CA-B2C30B9FA8FE","versionEndExcluding":"6.18.21","versionStartIncluding":"6.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"4CA2E747-A9EC-4518-9AA2-B4247FC748B7","versionEndExcluding":"6.19.11","versionStartIncluding":"6.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.19:-:*:*:*:*:*:*","matchCriteriaId":"9E2DBD4C-9DD9-4DD3-87CB-A0070A789CEA","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.19:rc2:*:*:*:*:*:*","matchCriteriaId":"8D97ED16-D6B7-4445-889C-4D6DE2EDC49A","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.19:rc3:*:*:*:*:*:*","matchCriteriaId":"B2C2D5D4-9A4B-4CDF-8D71-D22EB5E97D5A","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.19:rc4:*:*:*:*:*:*","matchCriteriaId":"DFFB2843-A867-48EC-97D7-B106C7BBAED0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.19:rc5:*:*:*:*:*:*","matchCriteriaId":"3CD3FE23-1A10-47E6-AD7E-D67F1BE3C5E2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.19:rc6:*:*:*:*:*:*","matchCriteriaId":"9F39FC76-7D77-4064-94D3-A16C436FA8D1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*","matchCriteriaId":"F253B622-8837-4245-BCE5-A7BF8FC76A16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*","matchCriteriaId":"4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*","matchCriteriaId":"F666C8D8-6538-46D4-B318-87610DE64C34","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*","matchCriteriaId":"02259FDA-961B-47BC-AE7F-93D7EC6E90C2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*","matchCriteriaId":"58A9FEFF-C040-420D-8F0A-BFDAAA1DF258","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate p_idx bounds in ext4_ext_correct_indexes\n\next4_ext_correct_indexes() walks up the extent tree correcting\nindex entries when the first extent in a leaf is modified. Before\naccessing path[k].p_idx->ei_block, there is no validation that\np_idx falls within the valid range of index entries for that\nlevel.\n\nIf the on-disk extent header contains a corrupted or crafted\neh_entries value, p_idx can point past the end of the allocated\nbuffer, causing a slab-out-of-bounds read.\n\nFix this by validating path[k].p_idx against EXT_LAST_INDEX() at\nboth access sites: before the while loop and inside it. Return\n-EFSCORRUPTED if the index pointer is out of range, consistent\nwith how other bounds violations are handled in the ext4 extent\ntree code."}],"id":"CVE-2026-31449","lastModified":"2026-09-08T09:17:55.763","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":1.8,"impactScore":5.9,"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary"}]},"published":"2026-04-22T14:16:38.933","references":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/01bf1e0b997d82c0e353b51ed74ef99698043c33"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","url":"https://git.kernel.org/stable/c/10242e640b36b91ad03d25f3dc77854bbdff8358"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/2acb5c12ebd860f30e4faf67e6cc8c44ddfe5fe8"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","url":"https://git.kernel.org/stable/c/39d6e2b67651614bac0dc6592fa9836321910067"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/407c944f217c17d4343148011acafebc604d55e1"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","url":"https://git.kernel.org/stable/c/4d08401aa13f1531216f1a7ae281ca4806e90a5c"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/93f2e975ed658ce09db4d4c2877ca2c06540df83"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","url":"https://git.kernel.org/stable/c/c5839b34704c9c2f47f079451bdbb22de0da1ed1"},{"source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html"}],"sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","vulnStatus":"Modified","weaknesses":[{"description":[{"lang":"en","value":"CWE-125"}],"source":"nvd@nist.gov","type":"Primary"}]},"severity":"HIGH","source":"nvd","title":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate p_idx bounds in ext4_ext_correct_..."}