udf: Mark LVID buffer as uptodate before marking it dirty

Summary

CVECVE-2026-93140
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:18:08 UTC
Updated2026-09-17 17:18:08 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: udf: Mark LVID buffer as uptodate before marking it dirty When an I/O error occurs while writing the Logical Volume Integrity Descriptor (LVID) buffer to the block device, the block layer's completion handler (`end_buffer_write_sync()`) clears the `BH_Uptodate` flag on the buffer. However, the buffer still contains valid LVID data in memory. If the filesystem is subsequently remounted read-write or synced, `udf_open_lvid()` or `udf_sync_fs()` will modify the LVID buffer and call `mark_buffer_dirty()`. This triggers a spurious `WARN_ON_ONCE(!buffer_uptodate(bh))` warning in `mark_buffer_dirty()` because the buffer is not marked uptodate, even though its in-memory contents are valid and are about to be overwritten. To prevent this spurious warning, unconditionally set the `BH_Uptodate` flag before calling `mark_buffer_dirty()` in `udf_open_lvid()` and `udf_sync_fs()`. This acknowledges that the in-memory buffer is valid and matches the workaround previously applied to `udf_close_lvid()` in commit 853a0c25baf9 ("udf: Mark LVID buffer as uptodate before marking it dirty"). Extending this workaround ensures consistent behavior across all LVID updates. Buffer I/O error on dev loop0, logical block 128, lost sync page write ------------[ cut here ]------------ !buffer_uptodate(bh) WARNING: fs/buffer.c:1087 at mark_buffer_dirty+0x299/0x410 fs/buffer.c:1087 ... Call Trace: <TASK> udf_open_lvid+0x369/0x5b0 fs/udf/super.c:2078 udf_reconfigure+0x336/0x540 fs/udf/super.c:679 reconfigure_super+0x232/0x8f0 fs/super.c:1080 vfs_cmd_reconfigure fs/fsopen.c:268 [inline] vfs_fsconfig_locked+0x171/0x320 fs/fsopen.c:297 __do_sys_fsconfig fs/fsopen.c:463 [inline] __se_sys_fsconfig+0x6b9/0x810 fs/fsopen.c:350 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94 </TASK>

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 853a0c25baf96b028de1654bea1e0c8857eadf3d e6461ef34f91ad7dbffdf912b3d661a7dd892931 git Not specified
CNA Linux Linux affected 853a0c25baf96b028de1654bea1e0c8857eadf3d 359cea636f4a74a96c01a8050f155e12840c079a git Not specified
CNA Linux Linux affected 853a0c25baf96b028de1654bea1e0c8857eadf3d a4c4e38b356ad4c1f90478124922917489137c08 git Not specified
CNA Linux Linux affected 853a0c25baf96b028de1654bea1e0c8857eadf3d 8034ddf4751d9143c5ef7eebe3d4f33218fdd378 git Not specified
CNA Linux Linux affected 853a0c25baf96b028de1654bea1e0c8857eadf3d ee477e5204f764444e60699280abf5936c2a6ae6 git Not specified
CNA Linux Linux affected 853a0c25baf96b028de1654bea1e0c8857eadf3d 11afe1912140f79d5af3091a54b181ef72fce1a5 git Not specified
CNA Linux Linux affected 853a0c25baf96b028de1654bea1e0c8857eadf3d c4058355d27488a3cd31c60c032335f77c4fdcfc git Not specified
CNA Linux Linux affected 853a0c25baf96b028de1654bea1e0c8857eadf3d fb0601134c7e51728bd098abc6909315de1e5d86 git Not specified
CNA Linux Linux affected c7da4ed95a78e38fdaffb06eaf1a3f3318b1add6 git Not specified
CNA Linux Linux affected c005218328597211008a4d33a91e2952798e3556 git Not specified
CNA Linux Linux affected 1357ed0b4b9db30846377febb40a847d6103c991 git Not specified
CNA Linux Linux affected 43f4a516b2f5492bc597f3753b693ad8adc62748 git Not specified
CNA Linux Linux affected 2.6.27.62 2.6.28 semver Not specified
CNA Linux Linux affected 2.6.32.57 2.6.33 semver Not specified
CNA Linux Linux affected 3.0.21 3.1 semver Not specified
CNA Linux Linux affected 3.2.6 3.3 semver Not specified
CNA Linux Linux affected 3.3 Not specified
CNA Linux Linux unaffected 3.3 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/ee477e5204f764444e60699280abf5936c2a6ae6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8034ddf4751d9143c5ef7eebe3d4f33218fdd378 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e6461ef34f91ad7dbffdf912b3d661a7dd892931 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fb0601134c7e51728bd098abc6909315de1e5d86 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c4058355d27488a3cd31c60c032335f77c4fdcfc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/359cea636f4a74a96c01a8050f155e12840c079a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/11afe1912140f79d5af3091a54b181ef72fce1a5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a4c4e38b356ad4c1f90478124922917489137c08 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report