Junglewise Threat Intelligence

CVE-2026-45858: Linux Kernel ext4 stale data exposure in extent splitting

CVE-2026-45858 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ext4 file system could allow for the exposure of stale data. When the system attempts to organize large sections of disk space and encounters a temporary resource shortage, it may incorrectly mark uninitialized areas as containing valid data. This could result in a user or process reading old information that was previously stored on the disk, potentially leading to the leakage of sensitive data from deleted files.

Technical details

A flaw was found in the ext4 file system's extent management logic within the Linux kernel. When ext4_split_extent() attempts to split an unwritten extent and convert a portion to initialized, a failure in ext4_split_extent_at() due to ENOSPC (lack of space) can lead to the entire extent being marked as written. Specifically, if the zero-out operation occurs but the subsequent split fails, the kernel may leave a range of blocks marked as 'written' that actually contain stale data from previous disk usage. This is resolved by introducing the EXT4_EXT_DATA_PARTIAL_VALID1 flag to ensure that the first half of a split remains unwritten if the full operation cannot complete, preventing the exposure of uninitialized disk blocks.

Affected products

  • Linux Linux Kernel ext4 file system component

Timeline

  • 2025-11-29: patched: Initial patch authored by Zhang Yi
  • 2026-05-27: advisory: CVE-2026-45858 published by NVD

References