Improper control of a resource through its lifetime in Linux kernel - CVE-2026-45912
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in ext4 extent status tree handling when splitting an unwritten extent during direct I/O writes. A local user can trigger extent splitting and subsequent delayed buffer writes to cause a denial of service.
The issue can leave a stale hole extent in the extent status tree, leading to errors in space accounting.
How to mitigate CVE-2026-45912
Sources
- https://git.kernel.org/stable/c/4c2d9dac4d328244f9365b0a1fa27ec802821820
- https://git.kernel.org/stable/c/5b1f4290453314e11cd8e15c7baa8a9b76c19b23
- https://git.kernel.org/stable/c/692103feca376ae4298c92aa8828015d20f1d87b
- https://git.kernel.org/stable/c/8302b5b4aacdbb378f7b1216bb2ee782b5142415
- https://git.kernel.org/stable/c/8b4b19a2f96348d70bfa306ef7d4a13b0bcbea79
- https://git.kernel.org/stable/c/93b2ebbbcb2e63cfc21a1946dfe91d3aa7952036
- https://git.kernel.org/stable/c/96007fd3c106aea773c1afae2d6f64cceb6da208
- https://git.kernel.org/stable/c/9a2b95cdaf07785e2739199037bd9c0863ccc1be