ext4: drop extent cache when splitting extent fails
Summary
| CVE | CVE-2026-45899 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-27 14:17:04 UTC |
| Updated | 2026-06-25 21:09:27 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: ext4: drop extent cache when splitting extent fails When the split extent fails, we might leave some extents still being processed and return an error directly, which will result in stale extent entries remaining in the extent status tree. So drop all of the remaining potentially stale extents if the splitting fails. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.000240000 probability, percentile 0.073320000 (date 2026-06-01)
Problem Types: NVD-CWE-noinfo
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 6e54f8dfee359bbd58086c883ea8cffd5312999d git | Not specified |
| CNA | Linux | Linux | affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 337506dc652383c80839edb8d8dcdd8ff2129b4f git | Not specified |
| CNA | Linux | Linux | affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 dc7c9b9d03a59a7fe483574531327e650a4b4adc git | Not specified |
| CNA | Linux | Linux | affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 120c6bd7ca9d3e80a968b758cbb3fbd67570f132 git | Not specified |
| CNA | Linux | Linux | affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 808f3191498f300174523c54cab101e18795ae4e git | Not specified |
| CNA | Linux | Linux | affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 31bf37cf53ede8145e2bc62da803d4506da92975 git | Not specified |
| CNA | Linux | Linux | affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 79b592e8f1b435796cbc2722190368e3e8ffd7a1 git | Not specified |
| CNA | Linux | Linux | affected 3.12 | Not specified |
| CNA | Linux | Linux | unaffected 3.12 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.253 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.203 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.130 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.75 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.14 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.19.4 6.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/808f3191498f300174523c54cab101e18795ae4e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/31bf37cf53ede8145e2bc62da803d4506da92975 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/dc7c9b9d03a59a7fe483574531327e650a4b4adc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/337506dc652383c80839edb8d8dcdd8ff2129b4f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/120c6bd7ca9d3e80a968b758cbb3fbd67570f132 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/79b592e8f1b435796cbc2722190368e3e8ffd7a1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/6e54f8dfee359bbd58086c883ea8cffd5312999d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.