Junglewise Threat Intelligence

CVE-2026-92502: Linux kernel ext4 stale xarray tags on folios during writeback

CVE-2026-92502 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A bug in the Linux ext4 filesystem's data=journal mode can cause stale metadata tags to persist on memory pages during writeback, leaving dangling references that are not cleaned up when the filesystem is remounted read-only. This can result in data loss warnings and potential filesystem corruption when the system reboots, particularly under heavy I/O workloads.

Technical details

This vulnerability is a logic error in ext4's writeback path for data=journal mode. The root cause is that folio_clear_dirty_for_io() clears the PG_dirty page flag but leaves xarray tags (PAGECACHE_TAG_DIRTY and PAGECACHE_TAG_TOWRITE) set, which are normally cleared only by __folio_start_writeback(). In data=journal mode, jbd2 checkpoints data without touching these xarray tags. When writeback encounters clean folios during the mpage_prepare_extent_to_map() scan, it skips them before reaching ext4_bio_write_folio() where tag cleanup occurs. Attack vector is local (kernel memory handling); no network or privilege escalation is involved. An attacker cannot directly exploit this, but it causes filesystem consistency issues and potential data loss on unclean shutdown. The fix involves clearing xarray tags for skipped clean folios via writeback cycling, similar to the earlier commit f4a2b42e7891.

Affected products

  • Linux Linux kernel affected versions prior to fix

Timeline

  • 2026-09-17: disclosed

Related threats