-

CVE-2026-92501

ext4: drain in-flight DIO before buffered write fallback

In the Linux kernel, the following vulnerability has been resolved:

ext4: drain in-flight DIO before buffered write fallback

generic/746 started failing intermittently on ext3 (no-extent inodes).
The test triggers 'Page cache invalidation failure on direct I/O'
warnings and subsequent fsync returns -EIO. Adding a 50ms delay
between ext4_buffered_write_iter() and filemap_write_and_wait_range()
in ext4_dio_write_iter() makes the race almost always reproducible.

On no-extent inodes, DIO writes to holes cannot use unwritten extents,
so ext4_iomap_alloc() leaves m_flags=0 and ext4_map_blocks() returns 0.
The iomap layer then returns -ENOTBLK, causing fallback to buffered I/O.

The fallback path in ext4_dio_write_iter() calls
ext4_buffered_write_iter() which dirties pages, then does flush and
invalidate. However, there's an unprotected window between
ext4_buffered_write_iter() returning (with inode lock released) and
the subsequent flush+invalidate.

Concurrent async DIO completions from other threads can run
kiocb_invalidate_post_direct_write() during this window. If pages have
been re-dirtied, post-invalidation finds dirty pages and triggers the
warning, setting -EIO in the error sequence.

Consider a file with two 4k extents: [hole][written]. Thread A does
DIO to the written extent, while thread B does DIO spanning both:

  kworker A (4k DIO, allocated block)    kworker B (8k DIO, fallback)
  -----------------------------------    ----------------------------
  inode_lock_shared()                    inode_lock_shared()
  iomap_dio_rw():                        iomap_dio_rw():
    kiocb_invalidate_pages -> clean        iomap_begin -> -ENOTBLK
    submit_bio (async)                     dio->size = 0
  inode_unlock_shared()                  inode_unlock_shared()

  [bio pending in block layer]           /* fallback: lock released */
                                         ext4_buffered_write_iter()
                                           inode_lock(exclusive)
                                           generic_perform_write()
                                             -> dirty pages [0, 8k]
                                           inode_unlock(exclusive)

                                         /* pages dirty, no lock */
  [bio completes]                        filemap_write_and_wait_range()
  iomap_dio_complete()                     -> flush dirty pages
    kiocb_invalidate_post_direct_write() invalidate_mapping_pages()
      invalidate_inode_pages2_range()
      -> finds dirty page!
      -> dio_warn_stale_pagecache()
      -> errseq_set(-EIO)

This issue can be triggered through normal I/O paths, not just
intentionally overlapping DIO writes from userspace. For example,
generic/746 uses a loop device where multiple kworkers issue concurrent
I/O to the backing file. Additionally, when block_size < folio_size,
non-overlapping DIO writes that share a large folio can also trigger
the race.

Add inode_dio_wait() in ext4_buffered_write_iter() before
ext4_write_checks() to drain all in-flight DIO. This ensures that
all DIO clears existing pages before submitting IO (via
kiocb_invalidate_pages()), all BIO waits for all DIO to complete
(via inode_dio_wait()), and ext4_write_checks() observes the inode
size after all completed DIO so that ext4_block_zero_eof() does not
race with in-flight DIO, thus eliminating the race.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 378f32bab3714f04c4e0c3aee4129f6703805550
Version < fd7e0dab20837b9ea1eeef7c26f78ace8ac8258c
Status affected
Version 378f32bab3714f04c4e0c3aee4129f6703805550
Version < f0af3ae09fb72382da1a5371bf6761b0264668e4
Status affected
Version 378f32bab3714f04c4e0c3aee4129f6703805550
Version < 7341e234927ff215f1d5d0bcfe04b74f53af378d
Status affected
Version 378f32bab3714f04c4e0c3aee4129f6703805550
Version < 74eee4ff9698a65b2e6e15dac0e50d6526ad5f20
Status affected
Version 378f32bab3714f04c4e0c3aee4129f6703805550
Version < d47cdadd6e49023f7ee248048463807f1214f1ee
Status affected
Version 378f32bab3714f04c4e0c3aee4129f6703805550
Version < 4e4e3eec506247c8f8bd8aaa1eb25e67016681a5
Status affected
Version 378f32bab3714f04c4e0c3aee4129f6703805550
Version < 9fd3ffc3c51c9deaba99bd7b338fff2d08f52416
Status affected
Version 378f32bab3714f04c4e0c3aee4129f6703805550
Version < 15cdefd0c0522f9d5e12d947fa04f4c11649b699
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.5
Status affected
Version 0
Version < 5.5
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fd7e0dab20837b9ea1eeef7c26f78ace8ac8258c
https://git.kernel.org/stable/c/f0af3ae09fb72382da1a5371bf6761b0264668e4
https://git.kernel.org/stable/c/7341e234927ff215f1d5d0bcfe04b74f53af378d
https://git.kernel.org/stable/c/74eee4ff9698a65b2e6e15dac0e50d6526ad5f20
https://git.kernel.org/stable/c/d47cdadd6e49023f7ee248048463807f1214f1ee
https://git.kernel.org/stable/c/4e4e3eec506247c8f8bd8aaa1eb25e67016681a5
https://git.kernel.org/stable/c/9fd3ffc3c51c9deaba99bd7b338fff2d08f52416
https://git.kernel.org/stable/c/15cdefd0c0522f9d5e12d947fa04f4c11649b699