Memory leak in Linux kernel - CVE-2026-92494
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a buffer_head reference leak.
The vulnerability exists due to improper resource release in ext4_init_orphan_info() when processing orphan file blocks with an invalid magic value or checksum. A local user can cause ext4_init_orphan_info() to process such orphan file blocks to cause a buffer_head reference leak.
Affected software
How to mitigate CVE-2026-92494
External References
- https://git.kernel.org/stable/c/05704335803b69c1bfa8637b7ada942bf2ee8a41
- https://git.kernel.org/stable/c/1399f102d8a1855c1a38506057306ec79d0787d9
- https://git.kernel.org/stable/c/35fc83c65faf7949f5701bb34b20f822560a7718
- https://git.kernel.org/stable/c/6ec53ccab0d691b3c73e03d930343ca45987e88d
- https://git.kernel.org/stable/c/74637f7fef030e5fb2e835b7dfeb05efdc48e0fe
- https://git.kernel.org/stable/c/a9a6ec1298f9bc134b2c5db27d25bb10603b7113
- https://git.kernel.org/stable/c/e1e342d9a561c016b8531ec1f4dcefaad9d64954