Executive brief
A vulnerability in the Linux kernel's ext4 file system could allow for the exposure of stale data. When the system attempts to organize large sections of disk space and encounters a temporary resource shortage, it may incorrectly mark uninitialized areas as containing valid data. This could result in a user or process reading old information that was previously stored on the disk, potentially leading to the leakage of sensitive data from deleted files.
Technical details
A flaw was found in the ext4 file system's extent management logic within the Linux kernel. When ext4_split_extent() attempts to split an unwritten extent and convert a portion to initialized, a failure in ext4_split_extent_at() due to ENOSPC (lack of space) can lead to the entire extent being marked as written. Specifically, if the zero-out operation occurs but the subsequent split fails, the kernel may leave a range of blocks marked as 'written' that actually contain stale data from previous disk usage. This is resolved by introducing the EXT4_EXT_DATA_PARTIAL_VALID1 flag to ensure that the first half of a split remains unwritten if the full operation cannot complete, preventing the exposure of uninitialized disk blocks.
Affected products
- Linux Linux Kernel ext4 file system component
Timeline
- 2025-11-29: patched: Initial patch authored by Zhang Yi
- 2026-05-27: advisory: CVE-2026-45858 published by NVD
References
- https://git.kernel.org/stable/c/1bf6974822d1dba86cf11b5f05498581cf3488a2
- https://git.kernel.org/stable/c/58ddae5d77b1db3a27b891c75a8fa120239ac092
- https://git.kernel.org/stable/c/7015fcf473796e1d2d876f241bd9e0c36f3d4eef
- https://git.kernel.org/stable/c/d17857b4fb9ba5745b59be0ef38fd532991fccbf
- https://git.kernel.org/stable/c/d67c8ecf3d8fda9b8ef80e6f665d84b6d6ac9d88