Executive brief
A vulnerability was identified in the Linux kernel's ext4 filesystem that could allow local users to view 'stale' data from previously deleted files. This occurs due to an error in how the system manages disk space during certain high-performance write operations. If a specific disk-writing task fails due to lack of space, the system may incorrectly mark a section of the disk as containing valid data when it actually contains remnants of old files.
Technical details
A race condition or error handling failure exists in the ext4 filesystem when splitting unwritten extents during Direct I/O (DIO) or writeback with 'dioread_nolock' enabled. When 'ext4_split_extent_at()' fails (e.g., due to -ENOSPC), the 'EXT4_EXT_DATA_VALID2' flag may cause the entire on-disk extent to be converted to a 'written' state even if the second half of the split was not successfully initialized. If the subsequent DIO write fails, the on-disk extent remains marked as 'written', potentially exposing stale data from the underlying block device once the extent status tree cache is cleared. The fix involves removing the 'EXT4_GET_BLOCKS_CONVERT' flag during pre-IO splitting to ensure the extent is not prematurely marked as valid.
Affected products
- Linux Linux Kernel ext4 filesystem component
Timeline
- 2025-11-29: patched: Initial patch authored by Zhang Yi
- 2026-05-27: disclosed: CVE-2026-45985 published
References
- https://git.kernel.org/stable/c/2698731d25823267c29190cb578da9296a0c0d7b
- https://git.kernel.org/stable/c/2920ec61c98b9476781359f05b94da84e80f54d4
- https://git.kernel.org/stable/c/37555690f39f78ef69af347d9aff897e07445949
- https://git.kernel.org/stable/c/67cdb7bd7442bd3cdc6d6088bbb2df9be2fe936c
- https://git.kernel.org/stable/c/716e7439a5a9b18c3ff882c2f8c834b9ced1aaec
- https://git.kernel.org/stable/c/77e407967cd872cd75d7e4a691908e49c8e6b4d4
- https://git.kernel.org/stable/c/feaf2a80e78f89ee8a3464126077ba8683b62791