SB20260918225 - Memory leak in Linux kernel ext4
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory leak (CVE-ID: CVE-2026-92494)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a buffer_head reference leak.
The vulnerability exists due to improper resource release in ext4_init_orphan_info() when processing orphan file blocks with an invalid magic value or checksum. A local user can cause ext4_init_orphan_info() to process such orphan file blocks to cause a buffer_head reference leak.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/05704335803b69c1bfa8637b7ada942bf2ee8a41
- https://git.kernel.org/stable/c/1399f102d8a1855c1a38506057306ec79d0787d9
- https://git.kernel.org/stable/c/35fc83c65faf7949f5701bb34b20f822560a7718
- https://git.kernel.org/stable/c/6ec53ccab0d691b3c73e03d930343ca45987e88d
- https://git.kernel.org/stable/c/74637f7fef030e5fb2e835b7dfeb05efdc48e0fe
- https://git.kernel.org/stable/c/a9a6ec1298f9bc134b2c5db27d25bb10603b7113
- https://git.kernel.org/stable/c/e1e342d9a561c016b8531ec1f4dcefaad9d64954