Executive brief
A race condition was identified in the Linux kernel's ext4 filesystem that can lead to incorrect reports of data corruption. This issue occurs during specific memory management tasks, such as page migration, where the system may incorrectly believe the filesystem's block tracking (bitmaps) is inconsistent. While primarily resulting in false-positive error reports and potential system instability under heavy stress, it could impact the reliability of data operations on affected Linux servers.
Technical details
A race condition exists in the ext4 filesystem's `ext4_mb_load_buddy_gfp` function within `fs/ext4/mballoc.c`. The vulnerability is caused by the 'fast path' of `load_buddy` only incrementing a folio's reference count, which is insufficient to prevent concurrent folio migration. This allows a timing window where page migration and bitmap modification overlap, leading to `e4b` bitmap check failures and false-positive corruption reports. The fix involves checking the folio lock status in the fast path; if the folio is locked (indicating migration), the system now reverts to the slow path which properly acquires the lock to ensure synchronization. This issue is most prevalent under mixed huge-page workloads and stress tests.
Affected products
- Linux Linux kernel ext4 filesystem component
Timeline
- 2026-01-06: other: Patch authored by Yongjian Sun
- 2026-05-27: advisory: CVE-2026-45942 published by NVD
References
- https://git.kernel.org/stable/c/29a07d691d282faf38c33d4b61839b89399110f9
- https://git.kernel.org/stable/c/57e83bfbe1e412ac42daced2086f3c6f9a17bba0
- https://git.kernel.org/stable/c/bdc56a9c46b2a99c12313122b9352b619a2e719e
- https://git.kernel.org/stable/c/c05033cfc5c7699cd4df8d48cef94d01da755f24
- https://git.kernel.org/stable/c/f29709a7a3fc38f5015d850504762cdef0e151f9