From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-74308: ext4: fix kernel BUG in ext4_write_inline_data_end
Date: Sat, 15 Aug 2026 15:10:35 +0900 [thread overview]
Message-ID: <2026081551-CVE-2026-74308-60a2@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
ext4: fix kernel BUG in ext4_write_inline_data_end
When the data=journal mount option is used, the ext4_journalled_write_end()
function incorrectly calls ext4_write_inline_data_end() without checking
if the EXT4_STATE_MAY_INLINE_DATA flag is still set on the inode.
If a previous attempt to convert the inline data to an extent failed (e.g.
due to ENOSPC), the EXT4_STATE_MAY_INLINE_DATA flag is cleared, but
the EXT4_INODE_INLINE_DATA flag remains set. In this scenario, the next
call to ext4_write_begin() will not prepare the inline data xattr for
writing, but ext4_journalled_write_end() will incorrectly attempt to write
to it, triggering a BUG_ON(pos + len > EXT4_I(inode)->i_inline_size) in
ext4_write_inline_data() since i_inline_size was not expanded.
Fix this by ensuring that ext4_journalled_write_end() only calls
ext4_write_inline_data_end() if the EXT4_STATE_MAY_INLINE_DATA flag is
set, mirroring the behavior of ext4_write_end() and ext4_da_write_end().
The Linux kernel CVE team has assigned CVE-2026-74308 to this issue.
Affected and fixed versions
===========================
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 6.6.145 with commit 260830a9a706f5d335398236fc788ce32f220de1
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 6.12.97 with commit 9808ae9fae996afa942bd963a39c9b1cdeebd0bd
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 6.18.40 with commit f00f5c0dd55319bc33b76f72c853bda0e0a32eda
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 7.1.5 with commit 0ae42b51607240990614e0843f0d3529aaff62cc
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 7.2-rc1 with commit ad09aa45965d3fafaf9963bc78109b73c0f9ac8d
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-74308
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/ext4/inode.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/260830a9a706f5d335398236fc788ce32f220de1
https://git.kernel.org/stable/c/9808ae9fae996afa942bd963a39c9b1cdeebd0bd
https://git.kernel.org/stable/c/f00f5c0dd55319bc33b76f72c853bda0e0a32eda
https://git.kernel.org/stable/c/0ae42b51607240990614e0843f0d3529aaff62cc
https://git.kernel.org/stable/c/ad09aa45965d3fafaf9963bc78109b73c0f9ac8d
reply other threads:[~2026-08-15 6:34 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026081551-CVE-2026-74308-60a2@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.