SB20260905148 - Missing Encryption of Sensitive Data in Linux kernel ext4
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Encryption of Sensitive Data (CVE-ID: CVE-2026-80806)
CWE-ID: CWE-311 - Missing Encryption of Sensitive Data
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause sensitive data to be stored without encryption.
The vulnerability exists due to incorrect initialization order of encryption flags in the ext4 __ext4_new_inode() function when creating a new encrypted regular file on an ext4 filesystem mounted with dax=always. A local user can create a new encrypted regular file and write data to it to cause sensitive data to be stored without encryption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3392391b363a63ebb531d45318a729b1c998565b
- https://git.kernel.org/stable/c/458776af0061afec1014cb3cd0061e282e482e83
- https://git.kernel.org/stable/c/5959cad3cfa852ec07bbdaf9c17f4838a94a8e6c
- https://git.kernel.org/stable/c/a13f61ba9b2a7a4ff1f140949ccfad23c5313757
- https://git.kernel.org/stable/c/add98959b220935b243170214c787bc03044a44d
- https://git.kernel.org/stable/c/da32af420d6d466e247c43ac0b829edeac7ae0ad
- https://git.kernel.org/stable/c/e27bae352158c007143d5bb50f3af33a177c0a37
- https://git.kernel.org/stable/c/ed1cd834da65db127f1c30ff67e78f14825a06c1
- https://git.kernel.org/stable/c/f53b325068bca0b238c3e0d2eb7de9b1f2268cab