« Volver al listado

CVE-2026-93140

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

udf: Mark LVID buffer as uptodate before marking it dirty

When an I/O error occurs while writing the Logical Volume Integrity Descriptor (LVID) buffer to the block device, the block layer's completion handler (`end_buffer_write_sync()`) clears the `BH_Uptodate` flag on the buffer. However, the buffer still contains valid LVID data in memory. If the filesystem is subsequently remounted read-write or synced, `udf_open_lvid()` or `udf_sync_fs()` will modify the LVID buffer and call `mark_buffer_dirty()`.

Leer descripción completaMostrar menos

This triggers a spurious `WARN_ON_ONCE(!buffer_uptodate(bh))` warning in `mark_buffer_dirty()` because the buffer is not marked uptodate, even though its in-memory contents are valid and are about to be overwritten.

To prevent this spurious warning, unconditionally set the `BH_Uptodate` flag before calling `mark_buffer_dirty()` in `udf_open_lvid()` and `udf_sync_fs()`. This acknowledges that the in-memory buffer is valid and matches the workaround previously applied to `udf_close_lvid()` in commit 853a0c25baf9 ("udf: Mark LVID buffer as uptodate before marking it dirty"). Extending this workaround ensures consistent behavior across all LVID updates.

Detalles técnicos trazas, registros y código del informe original
Buffer I/O error on dev loop0, logical block 128, lost sync page write
------------[ cut here ]------------
!buffer_uptodate(bh)
WARNING: fs/buffer.c:1087 at mark_buffer_dirty+0x299/0x410 fs/buffer.c:1087
...
Call Trace:
 <TASK>
 udf_open_lvid+0x369/0x5b0 fs/udf/super.c:2078
 udf_reconfigure+0x336/0x540 fs/udf/super.c:679
 reconfigure_super+0x232/0x8f0 fs/super.c:1080
 vfs_cmd_reconfigure fs/fsopen.c:268 [inline]
 vfs_fsconfig_locked+0x171/0x320 fs/fsopen.c:297
 __do_sys_fsconfig fs/fsopen.c:463 [inline]
 __se_sys_fsconfig+0x6b9/0x810 fs/fsopen.c:350
 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
 </TASK>

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93140",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "853a0c25baf96b028de1654bea1e0c8857eadf3d",
              "lessThan": "e6461ef34f91ad7dbffdf912b3d661a7dd892931",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "853a0c25baf96b028de1654bea1e0c8857eadf3d",
              "lessThan": "359cea636f4a74a96c01a8050f155e12840c079a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "853a0c25baf96b028de1654bea1e0c8857eadf3d",
              "lessThan": "a4c4e38b356ad4c1f90478124922917489137c08",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "853a0c25baf96b028de1654bea1e0c8857eadf3d",
              "lessThan": "8034ddf4751d9143c5ef7eebe3d4f33218fdd378",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "853a0c25baf96b028de1654bea1e0c8857eadf3d",
              "lessThan": "ee477e5204f764444e60699280abf5936c2a6ae6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "853a0c25baf96b028de1654bea1e0c8857eadf3d",
              "lessThan": "11afe1912140f79d5af3091a54b181ef72fce1a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "853a0c25baf96b028de1654bea1e0c8857eadf3d",
              "lessThan": "c4058355d27488a3cd31c60c032335f77c4fdcfc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "853a0c25baf96b028de1654bea1e0c8857eadf3d",
              "lessThan": "fb0601134c7e51728bd098abc6909315de1e5d86",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c7da4ed95a78e38fdaffb06eaf1a3f3318b1add6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c005218328597211008a4d33a91e2952798e3556",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1357ed0b4b9db30846377febb40a847d6103c991",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "43f4a516b2f5492bc597f3753b693ad8adc62748",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2.6.27.62",
              "lessThan": "2.6.28",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.6.32.57",
              "lessThan": "2.6.33",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.0.21",
              "lessThan": "3.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.2.6",
              "lessThan": "3.3",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/udf/super.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/udf/super.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:08.973",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/11afe1912140f79d5af3091a54b181ef72fce1a5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/359cea636f4a74a96c01a8050f155e12840c079a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8034ddf4751d9143c5ef7eebe3d4f33218fdd378",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a4c4e38b356ad4c1f90478124922917489137c08",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c4058355d27488a3cd31c60c032335f77c4fdcfc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e6461ef34f91ad7dbffdf912b3d661a7dd892931",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ee477e5204f764444e60699280abf5936c2a6ae6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fb0601134c7e51728bd098abc6909315de1e5d86",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Mark LVID buffer as uptodate before marking it dirty\n\nWhen an I/O error occurs while writing the Logical Volume Integrity\nDescriptor (LVID) buffer to the block device, the block layer's completion\nhandler (`end_buffer_write_sync()`) clears the `BH_Uptodate` flag on the\nbuffer. However, the buffer still contains valid LVID data in memory. If\nthe filesystem is subsequently remounted read-write or synced,\n`udf_open_lvid()` or `udf_sync_fs()` will modify the LVID buffer and call\n`mark_buffer_dirty()`. This triggers a spurious\n`WARN_ON_ONCE(!buffer_uptodate(bh))` warning in `mark_buffer_dirty()`\nbecause the buffer is not marked uptodate, even though its in-memory\ncontents are valid and are about to be overwritten.\n\nTo prevent this spurious warning, unconditionally set the `BH_Uptodate`\nflag before calling `mark_buffer_dirty()` in `udf_open_lvid()` and\n`udf_sync_fs()`. This acknowledges that the in-memory buffer is valid and\nmatches the workaround previously applied to `udf_close_lvid()` in commit\n853a0c25baf9 (\"udf: Mark LVID buffer as uptodate before marking it dirty\").\nExtending this workaround ensures consistent behavior across all LVID\nupdates.\n\nBuffer I/O error on dev loop0, logical block 128, lost sync page write\n------------[ cut here ]------------\n!buffer_uptodate(bh)\nWARNING: fs/buffer.c:1087 at mark_buffer_dirty+0x299/0x410 fs/buffer.c:1087\n...\nCall Trace:\n <TASK>\n udf_open_lvid+0x369/0x5b0 fs/udf/super.c:2078\n udf_reconfigure+0x336/0x540 fs/udf/super.c:679\n reconfigure_super+0x232/0x8f0 fs/super.c:1080\n vfs_cmd_reconfigure fs/fsopen.c:268 [inline]\n vfs_fsconfig_locked+0x171/0x320 fs/fsopen.c:297\n __do_sys_fsconfig fs/fsopen.c:463 [inline]\n __se_sys_fsconfig+0x6b9/0x810 fs/fsopen.c:350\n do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94\n </TASK>"
    }
  ],
  "lastModified": "2026-09-17T17:18:08.973",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}