Junglewise Threat Intelligence

CVE-2026-72367: Linux kernel iomap integer underflow in concurrent truncate handling

CVE-2026-72367 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's iomap I/O mapping subsystem contains an integer underflow vulnerability in file write-back operations when a concurrent file truncate occurs. An attacker or local user could trigger this condition to cause corruption of file size metadata, leading to potential data loss or filesystem consistency issues.

Technical details

The vulnerability is an unsigned integer underflow in the iomap ioend.c file during write-back handling. When trimming io_size to account for end-of-file boundaries, the code performs the calculation `io_size = end_pos - io_offset` without checking if end_pos is less than io_offset. If end_pos drops below io_offset (due to concurrent file truncation sampling and writeback operations extending beyond block-aligned ranges), the subtraction results in a negative value that wraps to a very large unsigned 64-bit integer. This corrupted io_size value is then consumed by filesystem end_io paths for critical operations such as on-disk EOF updates and extent completion handling, leading to data corruption. The fix adds a guard condition to clamp io_size to zero when io_offset >= end_pos, preventing the underflow while preserving the intended behavior of trimming to valid data.

Affected products

  • Linux Linux kernel All versions with iomap support (fix applied after commit 51d20d1dacbe)

Timeline

  • 2026-08-15: disclosed
  • 2026-07-01: patched: Upstream patch merged; backported to stable series

References

Related threats