* CVE-2026-74308: ext4: fix kernel BUG in ext4_write_inline_data_end
@ 2026-08-15 6:10 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15 6:10 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
ext4: fix kernel BUG in ext4_write_inline_data_end
When the data=journal mount option is used, the ext4_journalled_write_end()
function incorrectly calls ext4_write_inline_data_end() without checking
if the EXT4_STATE_MAY_INLINE_DATA flag is still set on the inode.
If a previous attempt to convert the inline data to an extent failed (e.g.
due to ENOSPC), the EXT4_STATE_MAY_INLINE_DATA flag is cleared, but
the EXT4_INODE_INLINE_DATA flag remains set. In this scenario, the next
call to ext4_write_begin() will not prepare the inline data xattr for
writing, but ext4_journalled_write_end() will incorrectly attempt to write
to it, triggering a BUG_ON(pos + len > EXT4_I(inode)->i_inline_size) in
ext4_write_inline_data() since i_inline_size was not expanded.
Fix this by ensuring that ext4_journalled_write_end() only calls
ext4_write_inline_data_end() if the EXT4_STATE_MAY_INLINE_DATA flag is
set, mirroring the behavior of ext4_write_end() and ext4_da_write_end().
The Linux kernel CVE team has assigned CVE-2026-74308 to this issue.
Affected and fixed versions
===========================
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 6.6.145 with commit 260830a9a706f5d335398236fc788ce32f220de1
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 6.12.97 with commit 9808ae9fae996afa942bd963a39c9b1cdeebd0bd
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 6.18.40 with commit f00f5c0dd55319bc33b76f72c853bda0e0a32eda
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 7.1.5 with commit 0ae42b51607240990614e0843f0d3529aaff62cc
Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 7.2-rc1 with commit ad09aa45965d3fafaf9963bc78109b73c0f9ac8d
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-74308
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/ext4/inode.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/260830a9a706f5d335398236fc788ce32f220de1
https://git.kernel.org/stable/c/9808ae9fae996afa942bd963a39c9b1cdeebd0bd
https://git.kernel.org/stable/c/f00f5c0dd55319bc33b76f72c853bda0e0a32eda
https://git.kernel.org/stable/c/0ae42b51607240990614e0843f0d3529aaff62cc
https://git.kernel.org/stable/c/ad09aa45965d3fafaf9963bc78109b73c0f9ac8d
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-15 6:34 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15 6:10 CVE-2026-74308: ext4: fix kernel BUG in ext4_write_inline_data_end Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.