Answer in brief
CVE-2026-92494 records a Unknown severity vulnerability in ext4: fix buffer_head leak in ext4_init_orphan_info. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 <a9a6ec1298f9bc134b2c5db27d25bb10603b7113 || >=02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 <35fc83c65faf7949f5701bb34b20f822560a7718 || >=02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 <74637f7fef030e5fb2e835b7dfeb05efdc48e0fe || >=02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 <6ec53ccab0d691b3c73e03d930343ca45987e88d || >=02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 <1399f102d8a1855c1a38506057306ec79d0787d9 || >=02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 <e1e342d9a561c016b8531ec1f4dcefaad9d64954 || >=02f310fcf47fa9311d6ba2946a8d19e7d7d11f37 <05704335803b69c1bfa8637b7ada942bf2ee8a41 | a9a6ec1298f9bc134b2c5db27d25bb10603b7113, 35fc83c65faf7949f5701bb34b20f822560a7718, 74637f7fef030e5fb2e835b7dfeb05efdc48e0fe, 6ec53ccab0d691b3c73e03d930343ca45987e88d, 1399f102d8a1855c1a38506057306ec79d0787d9, e1e342d9a561c016b8531ec1f4dcefaad9d64954, 05704335803b69c1bfa8637b7ada942bf2ee8a41 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: ext4: fix buffer_head leak in ext4_init_orphan_info ext4_init_orphan_info() reads orphan file blocks with ext4_bread() and stores the returned buffer_head in oi->of_binfo[i].ob_bh. If ext4_bread() succeeds but the orphan block magic or checksum validation fails, the function jumps to out_free. However, the old out_free loop starts releasing buffers from i - 1, so the current buffer_head at index i is skipped. This leaks the buffer_head reference obtained by ext4_bread() on the bad magic and bad checksum error paths. Fix this by tracking the number of successfully read buffer_heads and releasing exactly those buffer_heads on the error path.
Quoted source text, attributed separately from HOL analysis.