{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89601","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.732Z","datePublished":"2026-09-11T19:45:04.667Z","dateUpdated":"2026-09-13T06:31:34.222Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:31:34.222Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next2: Fix lost inode updates for IS_SYNC inodes\n\next2_setsize() and ext2_xattr_set2() had a construct like:\n\n\tif (IS_SYNC(inode)) {\n\t\tsync_inode_metadata(inode, 1);\n\t} else {\n\t\tmark_inode_dirty(inode);\n\t}\n\nwhich leads to lost inode updates for IS_SYNC inodes because\nsync_inode_metadata() does anything only if the inode is already dirty\nand hence inode updates may be simply lost. Fix the problem by\nunconditionally marking the inode dirty and *then* call\nsync_inode_metadata()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - nfsd SETATTR/SETXATTR and ksmbd truncate/EA handling call notify_change()/vfs_setxattr() into ext2_setattr()/ext2_xattr_set2() when an ext2 volume is NFS/SMB-exported (NAS and embedded USB-storage appliances, including sync-mounted disks); a remote client with write access therefore reaches the lost IS_SYNC inode update without a local shell.\nAC:L - The attacker can put the target in the IS_SYNC state at will (owner-writable FS_IOC_SETFLAGS/chattr +S, or a sync-mounted export) and then deterministically truncate or set/remove xattrs; sync_inode_metadata() skips a clean inode every time, with no race or memory layout outside attacker control.\nPR:L - The path is gated only by ordinary VFS write checks (inode_permission MAY_WRITE, xattr_permission for user.* xattrs, or inode_owner_or_capable() for FS_IOC_SETFLAGS); an unprivileged local user or a low-privilege NFS/SMB client with write access to a file suffices, and no init-namespace capability is required.\nUI:N - The attacker performs every step themselves (setting the SYNC flag, truncating or changing xattrs/ACLs, and driving inode reclaim); no separate victim action such as mounting a crafted image is required.\nS:U - Impact is confined to filesystem metadata and file data on the host that mounted the ext2 volume; this is not a VM escape, IOMMU bypass, or other cross-authority boundary.\nC:H - Removing the last xattr on an IS_SYNC inode frees the EA block without persisting i_file_acl=0, leaving a dangling on-disk pointer; after that block is reused, ext2_xattr_get() memcpy()s its contents to userspace when the header looks valid, so the filesystem-level UAF discloses other files' data.\nI:H - The lost i_file_acl update leaves the on-disk inode pointing at a freed EA block, so a later in-place xattr write can corrupt whatever reused that block, including other users' files and metadata; intended-durable IS_SYNC size/ctime/ACL updates can also fail to land, corrupting filesystem state.\nA:H - Reloading the stale i_file_acl and reading an invalid reused EA block calls ext2_error(), which panics on errors=panic and remounts the volume read-only on errors=remount-ro; the resulting filesystem inconsistency can also render files and the volume unavailable."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ext2/inode.c","fs/ext2/xattr.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5efb3350230fef831167740e69e6db2861101186","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"356984d1a5c32e94810cbb6c8dc7d8ff2d4d919a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ext2/inode.c","fs/ext2/xattr.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5efb3350230fef831167740e69e6db2861101186"},{"url":"https://git.kernel.org/stable/c/356984d1a5c32e94810cbb6c8dc7d8ff2d4d919a"}],"title":"ext2: Fix lost inode updates for IS_SYNC inodes","x_generator":{"engine":"bippy-1.2.0"}}}}