Executive brief
The Linux kernel's iomap subsystem, which handles direct I/O file operations, has a memory leak when atomic write operations are requested but the I/O size doesn't match expectations. When this size check fails, pages attached to the I/O request are not properly released, potentially causing memory exhaustion over time if repeated.
Technical details
The vulnerability exists in fs/iomap/direct-io.c's iomap_dio_bio_iter_one() function. When bio_iov_iter_get_pages() or the bounce helper succeeds but constructs a short bio (fewer bytes than expected), the REQ_ATOMIC size check rejects the operation. However, the original error path only dropped the bio reference without releasing attached pages, causing a memory leak. The fix adds a new out_bio_release_pages error path that properly calls bio_iov_iter_unbounce() or bio_release_pages() before returning the error. No special authentication or network access is required; the vulnerability is triggered by local file I/O operations using atomic write flags.
Affected products
- Linux Linux kernel All versions with atomic write support (from 9e0933c21c12 onwards)
Timeline
- 2026-08-15: disclosed: Published in NVD
- 2026-06-12: patched: Upstream fix committed (681e452683b69a8e1a571cba0f238f8ceacf55d2)
- 2026-07-24: patched: Backport to stable kernels