CVE-2026-45892 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ext4: drop extent cache after doing PARTIAL_VALID1 zeroout When splitting an unwritten extent in the middle and converting it to initialized in ext4_split_extent() with the EXT4_EXT_MAY_ZEROOUT and EXT4_EXT_DATA_VALID2 flags set, it could leave a stale unwritten extent. Assume we have an unwritten file and buffered write in the middle of it without dioread_nolock enabled, it will allocate blocks as written extent. 0 A B N [UUUUUUUUUUUU] on-disk extent U: unwritten extent [UUUUUUUUUUUU] extent status tree [--DDDDDDDD--] D: valid data |<- ->| ----> this range needs to be initialized ext4_split_extent() first try to split this extent at B with EXT4_EXT_DATA_PARTIAL_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but ext4_split_extent_at() failed to split this extent due to temporary lack of space. It zeroout B to N and leave the entire extent as unwritten. 0 A B N [UUUUUUUUUUUU] on-disk extent [UUUUUUUUUUUU] extent status tree [--DDDDDDDDZZ] Z: zeroed data ext4_split_extent() then try to split this extent at A with EXT4_EXT_DATA_VALID2 flag set. This time, it split successfully and leave an written extent from A to N. 0 A B N [UUWWWWWWWWWW] on-disk extent W: written extent [UUUUUUUUUUUU] extent status tree [--DDDDDDDDZZ] Finally ext4_map_create_blocks() only insert extent A to B to the extent status tree, and leave an stale unwritten extent in the status tree. 0 A B N [UUWWWWWWWWWW] on-disk extent W: written extent [UUWWWWWWWWUU] extent status tree [--DDDDDDDDZZ] Fix this issue by always cached extent status entry after zeroing out the second part.
A vulnerability in the Linux kernel's ext4 file system can lead to improper management of unwritten extents. When an unwritten extent is split and converted to an initialized state, it may leave behind a stale unwritten extent. This issue arises in scenarios where there is a buffered write in the middle of an unwritten file, without the 'dioread_nolock' option enabled. The problem occurs because the extent handling function, 'ext4_split_extent()', fails to split the extent at the desired point due to temporary space constraints. As a result, the function zeros out part of the extent but leaves the entire extent marked as unwritten. Later, when the extent is successfully split, only the newly written portion is updated in the extent status tree, leaving a stale unwritten entry. This vulnerability affects several versions of the Linux kernel.
The vulnerability has been addressed in Linux kernel commits 6d882ea3b0931b43530d44149b79fcd4ffc13030, a1b962a821e7a52d48212ae269b45808b4411267, d8ee559fccdef713f058cfe5f2c03dc9b18be3b1 and f0931a5c17005a0c4fc35bd1a001245effc3354b. Users should upgrade to the latest version of the Linux kernel to apply this fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/28db4bfc6f82fd20e2aadb7fc162244109a4eb31 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6d882ea3b0931b43530d44149b79fcd4ffc13030 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a1b962a821e7a52d48212ae269b45808b4411267 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c2ee51d684adca7645e4aa74adca13f6750390bc | kernel.org | Patch |
| https://git.kernel.org/stable/c/d8ee559fccdef713f058cfe5f2c03dc9b18be3b1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f0931a5c17005a0c4fc35bd1a001245effc3354b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | 6.1.167 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 30, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |