Description
In the Linux kernel, the following vulnerability has been resolved:

iomap: release pages on atomic dio size mismatch

If bio_iov_iter_get_pages() or the bounce helper succeeds but builds a
short bio, the REQ_ATOMIC size check rejects it before submission. The
old error path only dropped the bio reference, leaving any pages already
attached to the bio unreleased.

Release or unbounce the pages before falling through to out_put_bio on
this error path.

This bug was reported by sashiko:
https://sashiko.dev/#/patchset/20260608073134.95964-1-changfengnan%40bytedance.com
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Linux kernel’s iomap subsystem. When an atomic dio operation creates a short bio, the REQ_ATOMIC size check rejects the before it is submitted. The legacy error handling path drops only the bio reference, leaving the pages attached to the bio unreleased. Consequently, kernel pages accumulate, potentially exhausting memory and allowing the system to become unstable or unavailable. This issue represents a classic kernel memory leak, which when exploited repeatedly can lead to a denial of service.

Affected Systems

Any installation running a Linux kernel that has not incorporated the patch referenced by the commits 27ddd3442fc6f698fb8577c7cfb243ddd81ea8c0 and 681e452683b69a8e1a571cba0f238f8ceacf55d2 remains vulnerable. The vendor and product are Linux:Linux, and version information is not specified in the CVE file; therefore all kernels lacking the fix should be considered at risk.

Risk and Exploitability

Based on the description, it is inferred that the vulnerability can only be triggered by privileged code capable of performing atomic dio operations, implying that an attacker must have kernel or root access. The CVSS score of 5.5 reflects a moderate impact, while the EPSS score of < 1% indicates a low exploitation probability; the vulnerability is not listed in the CISA KEV catalog. Nonetheless, an attacker who can repeatedly provoke the error path could drain kernel memory, leading to a local denial of service. The low EPSS and absent KEV designation do not eliminate the risk, which remains moderate when privileges are obtainable.

Generated by OpenCVE AI on August 18, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the kernel patch that releases pages on atomic dio size mismatch, as contained in the commits 27ddd3442fc6f698fb8577c7cfb243ddd81ea8c0 and 681e452683b69a8e1a571cba0f238f8ceacf55d2.
  • Upgrade to a Linux kernel release that includes the patch.
  • Reboot the system to load the updated kernel.

Generated by OpenCVE AI on August 18, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-401

Tue, 18 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-401

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iomap: release pages on atomic dio size mismatch If bio_iov_iter_get_pages() or the bounce helper succeeds but builds a short bio, the REQ_ATOMIC size check rejects it before submission. The old error path only dropped the bio reference, leaving any pages already attached to the bio unreleased. Release or unbounce the pages before falling through to out_put_bio on this error path. This bug was reported by sashiko: https://sashiko.dev/#/patchset/20260608073134.95964-1-changfengnan%40bytedance.com
Title iomap: release pages on atomic dio size mismatch
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:13:22.015Z

Reserved: 2026-08-09T03:40:39.922Z

Link: CVE-2026-72370

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:10.473

Modified: 2026-08-17T06:18:41.267

Link: CVE-2026-72370

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72370 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T19:30:04Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime