Answer in brief
CVE-2026-92501 records a Unknown severity vulnerability in ext4: drain in-flight DIO before buffered write fallback. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=378f32bab3714f04c4e0c3aee4129f6703805550 <fd7e0dab20837b9ea1eeef7c26f78ace8ac8258c || >=378f32bab3714f04c4e0c3aee4129f6703805550 <f0af3ae09fb72382da1a5371bf6761b0264668e4 || >=378f32bab3714f04c4e0c3aee4129f6703805550 <7341e234927ff215f1d5d0bcfe04b74f53af378d || >=378f32bab3714f04c4e0c3aee4129f6703805550 <74eee4ff9698a65b2e6e15dac0e50d6526ad5f20 || >=378f32bab3714f04c4e0c3aee4129f6703805550 <d47cdadd6e49023f7ee248048463807f1214f1ee || >=378f32bab3714f04c4e0c3aee4129f6703805550 <4e4e3eec506247c8f8bd8aaa1eb25e67016681a5 || >=378f32bab3714f04c4e0c3aee4129f6703805550 <9fd3ffc3c51c9deaba99bd7b338fff2d08f52416 || >=378f32bab3714f04c4e0c3aee4129f6703805550 <15cdefd0c0522f9d5e12d947fa04f4c11649b699 | fd7e0dab20837b9ea1eeef7c26f78ace8ac8258c, f0af3ae09fb72382da1a5371bf6761b0264668e4, 7341e234927ff215f1d5d0bcfe04b74f53af378d, 74eee4ff9698a65b2e6e15dac0e50d6526ad5f20, d47cdadd6e49023f7ee248048463807f1214f1ee, 4e4e3eec506247c8f8bd8aaa1eb25e67016681a5, 9fd3ffc3c51c9deaba99bd7b338fff2d08f52416, 15cdefd0c0522f9d5e12d947fa04f4c11649b699 |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: ext4: drain in-flight DIO before buffered write fallback generic/746 started failing intermittently on ext3 (no-extent inodes). The test triggers 'Page cache invalidation failure on direct I/O' warnings and subsequent fsync returns -EIO. Adding a 50ms delay between ext4_buffered_write_iter() and filemap_write_and_wait_range() in ext4_dio_write_iter() makes the race almost always reproducible. On no-extent inodes, DIO writes to holes cannot use unwritten extents, so ext4_iomap_alloc() leaves m_flags=0 and ext4_map_blocks() returns 0. The iomap layer then returns -ENOTBLK, causing fallback to buffered I/O. The fallback path in ext4_dio_write_iter() calls ext4_buffered_write_iter() which dirties pages, then does flush and invalidate. However, there's an unprotected window between ext4_buffered_write_iter() returning (with inode lock released) and the subsequent flush+invalidate. Concurrent async DIO completions from other threads can run kiocb_invalidate_post_direct_write() during this window. If pages have been re-dirtied, post-invalidation finds dirty pages and triggers the warning, setting -EIO in the error sequence. Consider a file with two 4k extents: [hole][written]. Thread A does DIO to the written extent, while thread B does DIO spanning both: kworker A (4k DIO, allocated block) kworker B (8k DIO, fallback) ----------------------------------- ---------------------------- inode_lock_shared() inode_lock_shared() iomap_dio_rw(): iomap_dio_rw(): kiocb_invalidate_pages -> clean iomap_begin -> -ENOTBLK submit_bio (async) dio->size = 0 inode_unlock_shared() inode_unlock_shared() [bio pending in block layer] /* fallback: lock released */ ext4_buffered_write_iter() inode_lock(exclusive) generic_perform_write() -> dirty pages [0, 8k] inode_unlock(exclusive) /* pages dirty, no lock */ [bio completes] filemap_write_and_wait_range() iomap_dio_complete() -> flush dirty pages kiocb_invalidate_post_direct_write() invalidate_mapping_pages() invalidate_inode_pages2_range() -> finds dirty page! -> dio_warn_stale_pagecache() -> errseq_set(-EIO) This issue can be triggered through normal I/O paths, not just intentionally overlapping DIO writes from userspace. For example, generic/746 uses a loop device where multiple kworkers issue concurrent I/O to the backing file. Additionally, when block_size < folio_size, non-overlapping DIO writes that share a large folio can also trigger the race. Add inode_dio_wait() in ext4_buffered_write_iter() before ext4_write_checks() to drain all in-flight DIO. This ensures that all DIO clears existing pages before submitting IO (via kiocb_invalidate_pages()), all BIO waits for all DIO to complete (via inode_dio_wait()), and ext4_write_checks() observes the inode size after all completed DIO so that ext4_block_zero_eof() does not race with in-flight DIO, thus eliminating the race.
Quoted source text, attributed separately from HOL analysis.