๐Ÿ” CVE Alert

CVE-2026-92501

UNKNOWN 0.0

ext4: drain in-flight DIO before buffered write fallback

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ext4: drain in-flight DIO before buffered write fallback generic/746 started failing intermittently on ext3 (no-extent inodes). The test triggers 'Page cache invalidation failure on direct I/O' warnings and subsequent fsync returns -EIO. Adding a 50ms delay between ext4_buffered_write_iter() and filemap_write_and_wait_range() in ext4_dio_write_iter() makes the race almost always reproducible. On no-extent inodes, DIO writes to holes cannot use unwritten extents, so ext4_iomap_alloc() leaves m_flags=0 and ext4_map_blocks() returns 0. The iomap layer then returns -ENOTBLK, causing fallback to buffered I/O. The fallback path in ext4_dio_write_iter() calls ext4_buffered_write_iter() which dirties pages, then does flush and invalidate. However, there's an unprotected window between ext4_buffered_write_iter() returning (with inode lock released) and the subsequent flush+invalidate. Concurrent async DIO completions from other threads can run kiocb_invalidate_post_direct_write() during this window. If pages have been re-dirtied, post-invalidation finds dirty pages and triggers the warning, setting -EIO in the error sequence. Consider a file with two 4k extents: [hole][written]. Thread A does DIO to the written extent, while thread B does DIO spanning both: kworker A (4k DIO, allocated block) kworker B (8k DIO, fallback) ----------------------------------- ---------------------------- inode_lock_shared() inode_lock_shared() iomap_dio_rw(): iomap_dio_rw(): kiocb_invalidate_pages -> clean iomap_begin -> -ENOTBLK submit_bio (async) dio->size = 0 inode_unlock_shared() inode_unlock_shared() [bio pending in block layer] /* fallback: lock released */ ext4_buffered_write_iter() inode_lock(exclusive) generic_perform_write() -> dirty pages [0, 8k] inode_unlock(exclusive) /* pages dirty, no lock */ [bio completes] filemap_write_and_wait_range() iomap_dio_complete() -> flush dirty pages kiocb_invalidate_post_direct_write() invalidate_mapping_pages() invalidate_inode_pages2_range() -> finds dirty page! -> dio_warn_stale_pagecache() -> errseq_set(-EIO) This issue can be triggered through normal I/O paths, not just intentionally overlapping DIO writes from userspace. For example, generic/746 uses a loop device where multiple kworkers issue concurrent I/O to the backing file. Additionally, when block_size < folio_size, non-overlapping DIO writes that share a large folio can also trigger the race. Add inode_dio_wait() in ext4_buffered_write_iter() before ext4_write_checks() to drain all in-flight DIO. This ensures that all DIO clears existing pages before submitting IO (via kiocb_invalidate_pages()), all BIO waits for all DIO to complete (via inode_dio_wait()), and ext4_write_checks() observes the inode size after all completed DIO so that ext4_block_zero_eof() does not race with in-flight DIO, thus eliminating the race.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
378f32bab3714f04c4e0c3aee4129f6703805550 < fd7e0dab20837b9ea1eeef7c26f78ace8ac8258c 378f32bab3714f04c4e0c3aee4129f6703805550 < f0af3ae09fb72382da1a5371bf6761b0264668e4 378f32bab3714f04c4e0c3aee4129f6703805550 < 7341e234927ff215f1d5d0bcfe04b74f53af378d 378f32bab3714f04c4e0c3aee4129f6703805550 < 74eee4ff9698a65b2e6e15dac0e50d6526ad5f20 378f32bab3714f04c4e0c3aee4129f6703805550 < d47cdadd6e49023f7ee248048463807f1214f1ee 378f32bab3714f04c4e0c3aee4129f6703805550 < 4e4e3eec506247c8f8bd8aaa1eb25e67016681a5 378f32bab3714f04c4e0c3aee4129f6703805550 < 9fd3ffc3c51c9deaba99bd7b338fff2d08f52416 378f32bab3714f04c4e0c3aee4129f6703805550 < 15cdefd0c0522f9d5e12d947fa04f4c11649b699
Linux / Linux
5.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/fd7e0dab20837b9ea1eeef7c26f78ace8ac8258c git.kernel.org: https://git.kernel.org/stable/c/f0af3ae09fb72382da1a5371bf6761b0264668e4 git.kernel.org: https://git.kernel.org/stable/c/7341e234927ff215f1d5d0bcfe04b74f53af378d git.kernel.org: https://git.kernel.org/stable/c/74eee4ff9698a65b2e6e15dac0e50d6526ad5f20 git.kernel.org: https://git.kernel.org/stable/c/d47cdadd6e49023f7ee248048463807f1214f1ee git.kernel.org: https://git.kernel.org/stable/c/4e4e3eec506247c8f8bd8aaa1eb25e67016681a5 git.kernel.org: https://git.kernel.org/stable/c/9fd3ffc3c51c9deaba99bd7b338fff2d08f52416 git.kernel.org: https://git.kernel.org/stable/c/15cdefd0c0522f9d5e12d947fa04f4c11649b699