From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B80C54968FC for ; Fri, 4 Sep 2026 15:18:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535090; cv=none; b=UYiKGkoUrEfhrmbC6EUr1g7fbuzrWSy5fKyxLk7uKn2qwAPn1PTgZXloEpWj/d9JxGhD9yqCnVaU1kD4aBtvLTn7JUOp+TaNb6hJuAL4jtdtfviGYGwA9x0v6BDQKtVt1SA9Pt5uHhUU2PRDYmBxPa9Yhc1H3dqYJ5AOOo0dI1k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535090; c=relaxed/simple; bh=Uu56A/RagsjqyNyX2C77NCDrSSxp5IoAYULEtL36h4E=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=dil1PNn3BOhrO/j+ll1yy3mKZrNgGZLb1t4bUvISxKy4cN5E8Hjk6q6/fF2v2a/zcUloLKYSVvc3RuocqN6+ZQB8GnUkUZAHwrQlPcPZ2A3gr3UgxwUPW0z/b0DlC29erV6+iEgRdRSZoGxIW537xyje6JTBsVmy842/02g0WIM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=DOT3UIwY; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="DOT3UIwY" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8E8B41F00A3D; Fri, 4 Sep 2026 15:18:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788535088; bh=9sCxyJUMVQN3yXF5NATCptYEmgLpkD7ZiIe9o6Na0iU=; h=From:To:Cc:Subject:Date:Reply-To; b=DOT3UIwYcG7FjQepoZ4uA6XDZiG3YpE9q8LswrhnznUlwnd0p825TnZ8cAgIrVGHv kRcuH38L8l3hytFX0bMxCftVuaebMW/ItzHh6qiI6WmJKg/Ic/D80yy6vAOyVEzxbm +Yslrm0HoPXlUPe5aRRMzxcVdFrYP944sCLiyfGA= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80806: ext4: don't enable DAX on new encrypted files Date: Fri, 4 Sep 2026 17:11:45 +0200 Message-ID: <2026090410-CVE-2026-80806-ced9@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4659; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=HJQzwIxs74RoBVWwb+PJjPeVvNub5T0Y2+82DpVzpUo=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7vdVG66QOiP7Iv9hkE3jjqlu3fuvm/1eLy320NuRP 2Dp9ZtTO2JZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAiu0oZ5sdM9SmPlJ3PmO/R ck1cd4rx9+QHCxjml+csnfkvu/bx7/Afifk3W+87nWvfCgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ext4: don't enable DAX on new encrypted files Currently, when a new encrypted regular file is created, the call to ext4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made before EXT4_INODE_ENCRYPT is set. As a result, it can set S_DAX if the filesystem is mounted with "-o dax=always". EXT4_INODE_ENCRYPT then actually gets set a bit later in __ext4_new_inode(), when it calls fscrypt_set_context() which calls ext4_set_context(). ext4_set_context() sets EXT4_INODE_ENCRYPT and calls ext4_set_inode_flags(inode, init=false) to set S_ENCRYPTED too. This was intended to clear S_DAX as well. However, this was broken by commit 043546e46dc7 ("fs/ext4: Only change S_DAX on inode load"). This causes data written to the file to bypass encryption, also causing xfstests failures such as generic/548 (when "-o dax=always" is used). Fix this by simplifying the flow by making __ext4_new_inode() set EXT4_INODE_ENCRYPT earlier. This makes it take effect in ext4_set_inode_flags(inode, init=true), making S_DAX never be set. Similarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first place on new encrypted inodes. Then it doesn't need to be cleared. As a result of these simplifications, ext4_set_context() no longer needs to change inode flags or state when 'handle != NULL'. Remove that too. The Linux kernel CVE team has assigned CVE-2026-80806 to this issue. Affected and fixed versions =========================== Issue introduced in 5.8 with commit 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 and fixed in 5.10.269 with commit add98959b220935b243170214c787bc03044a44d Issue introduced in 5.8 with commit 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 and fixed in 5.15.220 with commit f53b325068bca0b238c3e0d2eb7de9b1f2268cab Issue introduced in 5.8 with commit 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 and fixed in 6.1.187 with commit 5959cad3cfa852ec07bbdaf9c17f4838a94a8e6c Issue introduced in 5.8 with commit 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 and fixed in 6.6.156 with commit a13f61ba9b2a7a4ff1f140949ccfad23c5313757 Issue introduced in 5.8 with commit 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 and fixed in 6.12.108 with commit ed1cd834da65db127f1c30ff67e78f14825a06c1 Issue introduced in 5.8 with commit 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 and fixed in 6.18.47 with commit 458776af0061afec1014cb3cd0061e282e482e83 Issue introduced in 5.8 with commit 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 and fixed in 7.1.11 with commit 3392391b363a63ebb531d45318a729b1c998565b Issue introduced in 5.8 with commit 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 and fixed in 7.2.1 with commit e27bae352158c007143d5bb50f3af33a177c0a37 Issue introduced in 5.8 with commit 043546e46dc70c25ff7e2cf6d09cbb0424fc9978 and fixed in 7.3-rc1 with commit da32af420d6d466e247c43ac0b829edeac7ae0ad Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80806 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/ext4/crypto.c fs/ext4/ialloc.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/add98959b220935b243170214c787bc03044a44d https://git.kernel.org/stable/c/f53b325068bca0b238c3e0d2eb7de9b1f2268cab https://git.kernel.org/stable/c/5959cad3cfa852ec07bbdaf9c17f4838a94a8e6c https://git.kernel.org/stable/c/a13f61ba9b2a7a4ff1f140949ccfad23c5313757 https://git.kernel.org/stable/c/ed1cd834da65db127f1c30ff67e78f14825a06c1 https://git.kernel.org/stable/c/458776af0061afec1014cb3cd0061e282e482e83 https://git.kernel.org/stable/c/3392391b363a63ebb531d45318a729b1c998565b https://git.kernel.org/stable/c/e27bae352158c007143d5bb50f3af33a177c0a37 https://git.kernel.org/stable/c/da32af420d6d466e247c43ac0b829edeac7ae0ad