From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5971D381EBE for ; Sat, 15 Aug 2026 06:34:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775648; cv=none; b=izNzcuCelEesE5iHpKIbA90Jy0ah0grVAcQfYPr/hBcOA3tH5aGVvXPjzpYbSJ4LLRH5NJP10+RTFvyBy3Rnwmo+Skjmoo44yf0mh+P9Q2vA0h8bJL5L7uXHAfmuXnV3zOsOCeHZ62qxGnydiYXtLsxDL8rws9/q4ePpLEMPf5k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775648; c=relaxed/simple; bh=pGwkaJO73V1fQ0YQr04RoIfNJ3vPiV478e1QSvqLOGg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=EPmXpkTBj5hBVcVnRbDZaadW5lSyuPYIYWuWUIVcSmKxpAqnfIeU9jb4MUNcPd985EecKmVdMaKPYZ7140V51UhRi36D2KJ2BM2ODVNSUUTyi7asl9z4azy325SuyIEKdAmYcKOQFwJz60k3GN1x/3zKTHX2mU2Bs9SgIxcCDFg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=HqLLWSu/; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="HqLLWSu/" Received: by smtp.kernel.org (Postfix) with ESMTPSA id AF9AC1F000E9; Sat, 15 Aug 2026 06:34:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786775647; bh=rIzCO91SLZfo+b3I7r+6s2dKqGTede9I3vnglHVFAio=; h=From:To:Cc:Subject:Date:Reply-To; b=HqLLWSu/tONXNDhf6+8Hxy6tVlXKxA/yo8FOBWL6ftnnTrgjTZTpy/kJr6FZQL8Lf 3aPW8Yrj7ZN9A+kYn78pD70T1bV2aEF9gojMuLNt82zcGt3XpGez+GFN9D+hR7rZng iLUlpJQFYb8YGvfpJbYGR/YOEdu0DSfYut51COk4= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-74308: ext4: fix kernel BUG in ext4_write_inline_data_end Date: Sat, 15 Aug 2026 15:10:35 +0900 Message-ID: <2026081551-CVE-2026-74308-60a2@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3367; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=LiXgOquhL/fzjMwYYxhaAkfQgKqdnESI4Bmj8+ZopqM=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNjNzHzux45SPf9W6GYNrGVvcN0R/P99XyCnxayydm2 VzVdau8I5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACbSW8Uwv/Ky0jGvibuydv2M K5CS4j+zwN2xnGHBwjVH9zNOtJjRMEvAOnb5C+78PRULAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ext4: fix kernel BUG in ext4_write_inline_data_end When the data=journal mount option is used, the ext4_journalled_write_end() function incorrectly calls ext4_write_inline_data_end() without checking if the EXT4_STATE_MAY_INLINE_DATA flag is still set on the inode. If a previous attempt to convert the inline data to an extent failed (e.g. due to ENOSPC), the EXT4_STATE_MAY_INLINE_DATA flag is cleared, but the EXT4_INODE_INLINE_DATA flag remains set. In this scenario, the next call to ext4_write_begin() will not prepare the inline data xattr for writing, but ext4_journalled_write_end() will incorrectly attempt to write to it, triggering a BUG_ON(pos + len > EXT4_I(inode)->i_inline_size) in ext4_write_inline_data() since i_inline_size was not expanded. Fix this by ensuring that ext4_journalled_write_end() only calls ext4_write_inline_data_end() if the EXT4_STATE_MAY_INLINE_DATA flag is set, mirroring the behavior of ext4_write_end() and ext4_da_write_end(). The Linux kernel CVE team has assigned CVE-2026-74308 to this issue. Affected and fixed versions =========================== Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 6.6.145 with commit 260830a9a706f5d335398236fc788ce32f220de1 Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 6.12.97 with commit 9808ae9fae996afa942bd963a39c9b1cdeebd0bd Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 6.18.40 with commit f00f5c0dd55319bc33b76f72c853bda0e0a32eda Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 7.1.5 with commit 0ae42b51607240990614e0843f0d3529aaff62cc Issue introduced in 3.8 with commit 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb and fixed in 7.2-rc1 with commit ad09aa45965d3fafaf9963bc78109b73c0f9ac8d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74308 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/ext4/inode.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/260830a9a706f5d335398236fc788ce32f220de1 https://git.kernel.org/stable/c/9808ae9fae996afa942bd963a39c9b1cdeebd0bd https://git.kernel.org/stable/c/f00f5c0dd55319bc33b76f72c853bda0e0a32eda https://git.kernel.org/stable/c/0ae42b51607240990614e0843f0d3529aaff62cc https://git.kernel.org/stable/c/ad09aa45965d3fafaf9963bc78109b73c0f9ac8d