« Volver al listado

CVE-2026-92494

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ext4: fix buffer_head leak in ext4_init_orphan_info

ext4_init_orphan_info() reads orphan file blocks with ext4_bread() and stores the returned buffer_head in oi->of_binfo[i].ob_bh.

If ext4_bread() succeeds but the orphan block magic or checksum validation fails, the function jumps to out_free. However, the old out_free loop starts releasing buffers from i - 1, so the current buffer_head at index i is skipped.

This leaks the buffer_head reference obtained by ext4_bread() on the bad magic and bad checksum error paths.

Fix this by tracking the number of successfully read buffer_heads and releasing exactly those buffer_heads on the error path.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-92494",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "02f310fcf47fa9311d6ba2946a8d19e7d7d11f37",
              "lessThan": "a9a6ec1298f9bc134b2c5db27d25bb10603b7113",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02f310fcf47fa9311d6ba2946a8d19e7d7d11f37",
              "lessThan": "35fc83c65faf7949f5701bb34b20f822560a7718",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02f310fcf47fa9311d6ba2946a8d19e7d7d11f37",
              "lessThan": "74637f7fef030e5fb2e835b7dfeb05efdc48e0fe",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02f310fcf47fa9311d6ba2946a8d19e7d7d11f37",
              "lessThan": "6ec53ccab0d691b3c73e03d930343ca45987e88d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02f310fcf47fa9311d6ba2946a8d19e7d7d11f37",
              "lessThan": "1399f102d8a1855c1a38506057306ec79d0787d9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02f310fcf47fa9311d6ba2946a8d19e7d7d11f37",
              "lessThan": "e1e342d9a561c016b8531ec1f4dcefaad9d64954",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02f310fcf47fa9311d6ba2946a8d19e7d7d11f37",
              "lessThan": "05704335803b69c1bfa8637b7ada942bf2ee8a41",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/ext4/orphan.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/ext4/orphan.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:51.547",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/05704335803b69c1bfa8637b7ada942bf2ee8a41",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1399f102d8a1855c1a38506057306ec79d0787d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/35fc83c65faf7949f5701bb34b20f822560a7718",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6ec53ccab0d691b3c73e03d930343ca45987e88d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/74637f7fef030e5fb2e835b7dfeb05efdc48e0fe",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a9a6ec1298f9bc134b2c5db27d25bb10603b7113",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e1e342d9a561c016b8531ec1f4dcefaad9d64954",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix buffer_head leak in ext4_init_orphan_info\n\next4_init_orphan_info() reads orphan file blocks with ext4_bread()\nand stores the returned buffer_head in oi->of_binfo[i].ob_bh.\n\nIf ext4_bread() succeeds but the orphan block magic or checksum\nvalidation fails, the function jumps to out_free. However, the old\nout_free loop starts releasing buffers from i - 1, so the current\nbuffer_head at index i is skipped.\n\nThis leaks the buffer_head reference obtained by ext4_bread() on the\nbad magic and bad checksum error paths.\n\nFix this by tracking the number of successfully read buffer_heads and\nreleasing exactly those buffer_heads on the error path."
    }
  ],
  "lastModified": "2026-09-17T17:17:51.547",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}