Executive brief
A vulnerability exists in the Linux kernel's ext4 filesystem, which is widely used for data storage. If a storage device contains a corrupted filesystem, attempting to read certain files could cause the entire system to crash (kernel panic). This issue has been resolved by improving how the system handles these errors, allowing it to report the corruption without shutting down.
Technical details
A vulnerability in fs/ext4/inline.c was identified where ext4_read_inline_folio (or ext4_read_inline_page in older kernels) lacked sufficient bounds checking. Specifically, if a corrupted filesystem reports an inline data size exceeding the system's PAGE_SIZE, the kernel would either trigger a BUG_ON() assertion (causing a panic) or perform an out-of-bounds memory write during data copying. The fix replaces the assertion with proper error handling that logs the corruption via ext4_error_inode(), releases the buffer head to prevent memory leaks, and returns -EFSCORRUPTED. This prevents local denial-of-service and potential memory corruption when mounting or reading from malicious or damaged ext4 volumes.
Affected products
- Linux Linux Kernel 3.8 to 6.19.11, 6.18.21, 6.12.80, 6.6.131
Timeline
- 2026-02-23: disclosed: Initial patch submission by Yuto Ohnuki
- 2026-03-27: patched: Patch committed to mainline kernel
- 2026-04-22: advisory: CVE published in NVD
References
- https://git.kernel.org/stable/c/3462a3f0716d27af51896dc8688bcf0628fb17ee
- https://git.kernel.org/stable/c/356227096eb66e41b23caf7045e6304877322edf
- https://git.kernel.org/stable/c/636e8d85a36ab6c31aafd04ee66a69b18eebee7b
- https://git.kernel.org/stable/c/65c6c30ce6362c1c684568744ea510c921a756cd
- https://git.kernel.org/stable/c/823849a26af089ffc5dfdd2ae4b9d446b46a0cda
- https://git.kernel.org/stable/c/a7d600e04732a7d29b107c91fe3aec64cf6ce7f2
- https://git.kernel.org/stable/c/af25a6affeac4919e8d8c5cccc01a9d53478447e