-

CVE-2026-92494

ext4: fix buffer_head leak in ext4_init_orphan_info

In the Linux kernel, the following vulnerability has been resolved:

ext4: fix buffer_head leak in ext4_init_orphan_info

ext4_init_orphan_info() reads orphan file blocks with ext4_bread()
and stores the returned buffer_head in oi->of_binfo[i].ob_bh.

If ext4_bread() succeeds but the orphan block magic or checksum
validation fails, the function jumps to out_free. However, the old
out_free loop starts releasing buffers from i - 1, so the current
buffer_head at index i is skipped.

This leaks the buffer_head reference obtained by ext4_bread() on the
bad magic and bad checksum error paths.

Fix this by tracking the number of successfully read buffer_heads and
releasing exactly those buffer_heads on the error path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37
Version < a9a6ec1298f9bc134b2c5db27d25bb10603b7113
Status affected
Version 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37
Version < 35fc83c65faf7949f5701bb34b20f822560a7718
Status affected
Version 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37
Version < 74637f7fef030e5fb2e835b7dfeb05efdc48e0fe
Status affected
Version 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37
Version < 6ec53ccab0d691b3c73e03d930343ca45987e88d
Status affected
Version 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37
Version < 1399f102d8a1855c1a38506057306ec79d0787d9
Status affected
Version 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37
Version < e1e342d9a561c016b8531ec1f4dcefaad9d64954
Status affected
Version 02f310fcf47fa9311d6ba2946a8d19e7d7d11f37
Version < 05704335803b69c1bfa8637b7ada942bf2ee8a41
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.11
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a9a6ec1298f9bc134b2c5db27d25bb10603b7113
https://git.kernel.org/stable/c/35fc83c65faf7949f5701bb34b20f822560a7718
https://git.kernel.org/stable/c/74637f7fef030e5fb2e835b7dfeb05efdc48e0fe
https://git.kernel.org/stable/c/6ec53ccab0d691b3c73e03d930343ca45987e88d
https://git.kernel.org/stable/c/1399f102d8a1855c1a38506057306ec79d0787d9
https://git.kernel.org/stable/c/e1e342d9a561c016b8531ec1f4dcefaad9d64954
https://git.kernel.org/stable/c/05704335803b69c1bfa8637b7ada942bf2ee8a41