{"api_version":"1","generated_at":"2026-07-23T10:55:00+00:00","cve":"CVE-2026-45899","urls":{"html":"https://cve.report/CVE-2026-45899","api":"https://cve.report/api/cve/CVE-2026-45899.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-45899","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-45899"},"summary":{"title":"ext4: drop extent cache when splitting extent fails","description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: drop extent cache when splitting extent fails\n\nWhen the split extent fails, we might leave some extents still being\nprocessed and return an error directly, which will result in stale\nextent entries remaining in the extent status tree. So drop all of the\nremaining potentially stale extents if the splitting fails.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-05-27 14:17:04","updated_at":"2026-06-25 21:09:27"},"problem_types":["NVD-CWE-noinfo"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}}],"references":[{"url":"https://git.kernel.org/stable/c/808f3191498f300174523c54cab101e18795ae4e","name":"https://git.kernel.org/stable/c/808f3191498f300174523c54cab101e18795ae4e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/31bf37cf53ede8145e2bc62da803d4506da92975","name":"https://git.kernel.org/stable/c/31bf37cf53ede8145e2bc62da803d4506da92975","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/dc7c9b9d03a59a7fe483574531327e650a4b4adc","name":"https://git.kernel.org/stable/c/dc7c9b9d03a59a7fe483574531327e650a4b4adc","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/337506dc652383c80839edb8d8dcdd8ff2129b4f","name":"https://git.kernel.org/stable/c/337506dc652383c80839edb8d8dcdd8ff2129b4f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/120c6bd7ca9d3e80a968b758cbb3fbd67570f132","name":"https://git.kernel.org/stable/c/120c6bd7ca9d3e80a968b758cbb3fbd67570f132","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/79b592e8f1b435796cbc2722190368e3e8ffd7a1","name":"https://git.kernel.org/stable/c/79b592e8f1b435796cbc2722190368e3e8ffd7a1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6e54f8dfee359bbd58086c883ea8cffd5312999d","name":"https://git.kernel.org/stable/c/6e54f8dfee359bbd58086c883ea8cffd5312999d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-45899","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45899","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 6e54f8dfee359bbd58086c883ea8cffd5312999d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 337506dc652383c80839edb8d8dcdd8ff2129b4f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 dc7c9b9d03a59a7fe483574531327e650a4b4adc git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 120c6bd7ca9d3e80a968b758cbb3fbd67570f132 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 808f3191498f300174523c54cab101e18795ae4e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 31bf37cf53ede8145e2bc62da803d4506da92975 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 107a7bd31ac003e42c0f966aa8e5b26947de6024 79b592e8f1b435796cbc2722190368e3e8ffd7a1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.12","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.253 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.203 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.130 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.75 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.14 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.19.4 6.19.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"45899","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"45899","cve":"CVE-2026-45899","epss":"0.000240000","percentile":"0.073320000","score_date":"2026-06-01","updated_at":"2026-06-02 00:05:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/ext4/extents.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"6e54f8dfee359bbd58086c883ea8cffd5312999d","status":"affected","version":"107a7bd31ac003e42c0f966aa8e5b26947de6024","versionType":"git"},{"lessThan":"337506dc652383c80839edb8d8dcdd8ff2129b4f","status":"affected","version":"107a7bd31ac003e42c0f966aa8e5b26947de6024","versionType":"git"},{"lessThan":"dc7c9b9d03a59a7fe483574531327e650a4b4adc","status":"affected","version":"107a7bd31ac003e42c0f966aa8e5b26947de6024","versionType":"git"},{"lessThan":"120c6bd7ca9d3e80a968b758cbb3fbd67570f132","status":"affected","version":"107a7bd31ac003e42c0f966aa8e5b26947de6024","versionType":"git"},{"lessThan":"808f3191498f300174523c54cab101e18795ae4e","status":"affected","version":"107a7bd31ac003e42c0f966aa8e5b26947de6024","versionType":"git"},{"lessThan":"31bf37cf53ede8145e2bc62da803d4506da92975","status":"affected","version":"107a7bd31ac003e42c0f966aa8e5b26947de6024","versionType":"git"},{"lessThan":"79b592e8f1b435796cbc2722190368e3e8ffd7a1","status":"affected","version":"107a7bd31ac003e42c0f966aa8e5b26947de6024","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/ext4/extents.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.12"},{"lessThan":"3.12","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.253","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.203","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.130","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.75","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.14","versionType":"semver"},{"lessThanOrEqual":"6.19.*","status":"unaffected","version":"6.19.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.0","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.253","versionStartIncluding":"3.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.203","versionStartIncluding":"3.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.130","versionStartIncluding":"3.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.75","versionStartIncluding":"3.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.14","versionStartIncluding":"3.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.19.4","versionStartIncluding":"3.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0","versionStartIncluding":"3.12","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: drop extent cache when splitting extent fails\n\nWhen the split extent fails, we might leave some extents still being\nprocessed and return an error directly, which will result in stale\nextent entries remaining in the extent status tree. So drop all of the\nremaining potentially stale extents if the splitting fails."}],"providerMetadata":{"dateUpdated":"2026-05-30T10:41:44.680Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/6e54f8dfee359bbd58086c883ea8cffd5312999d"},{"url":"https://git.kernel.org/stable/c/337506dc652383c80839edb8d8dcdd8ff2129b4f"},{"url":"https://git.kernel.org/stable/c/dc7c9b9d03a59a7fe483574531327e650a4b4adc"},{"url":"https://git.kernel.org/stable/c/120c6bd7ca9d3e80a968b758cbb3fbd67570f132"},{"url":"https://git.kernel.org/stable/c/808f3191498f300174523c54cab101e18795ae4e"},{"url":"https://git.kernel.org/stable/c/31bf37cf53ede8145e2bc62da803d4506da92975"},{"url":"https://git.kernel.org/stable/c/79b592e8f1b435796cbc2722190368e3e8ffd7a1"}],"title":"ext4: drop extent cache when splitting extent fails","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-45899","datePublished":"2026-05-27T12:17:08.447Z","dateReserved":"2026-05-13T15:03:33.083Z","dateUpdated":"2026-05-30T10:41:44.680Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-27 14:17:04","lastModifiedDate":"2026-06-25 21:09:27","problem_types":["NVD-CWE-noinfo"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.12","versionEndExcluding":"5.10.253","matchCriteriaId":"0ECA9FA3-7D5A-47DF-96CD-50ED0F72C020"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"5.15.203","matchCriteriaId":"20DDB3E9-AABF-4107-ADB0-5362AA067045"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.6.130","matchCriteriaId":"BA396CE4-960C-4CDD-8691-B9AE924E2BB0"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.12.75","matchCriteriaId":"BCE16369-98ED-41CF-8995-DFDC10B288D2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.14","matchCriteriaId":"BF463CB7-1F58-4607-B847-77ED23E4B9B7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"6.19.4","matchCriteriaId":"672A3E79-EC03-479D-8503-361DFBDC8092"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"45899","Ordinal":"1","Title":"ext4: drop extent cache when splitting extent fails","CVE":"CVE-2026-45899","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"45899","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: drop extent cache when splitting extent fails\n\nWhen the split extent fails, we might leave some extents still being\nprocessed and return an error directly, which will result in stale\nextent entries remaining in the extent status tree. So drop all of the\nremaining potentially stale extents if the splitting fails.","Type":"Description","Title":"ext4: drop extent cache when splitting extent fails"}]}}}