Description
In the Linux kernel, the following vulnerability has been resolved:

ext2: Fix lost inode updates for IS_SYNC inodes

ext2_setsize() and ext2_xattr_set2() had a construct like:

if (IS_SYNC(inode)) {
sync_inode_metadata(inode, 1);
} else {
mark_inode_dirty(inode);
}

which leads to lost inode updates for IS_SYNC inodes because
sync_inode_metadata() does anything only if the inode is already dirty
and hence inode updates may be simply lost. Fix the problem by
unconditionally marking the inode dirty and *then* call
sync_inode_metadata().
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Integrity / Possible Data Loss due to lost inode updates
Action: Apply Patch
AI Analysis

Impact

In the ext2 filesystem code of the Linux kernel, functions that set inode size or extended attributes used a pattern that only called sync_inode_metadata when the inode was already dirty. When an inode was marked with the IS_SYNC flag, this check caused any metadata writes to that inode to be lost because sync_inode_metadata alone does nothing unless the inode is dirty. Consequently, updates to the inode’s metadata could vanish, leading to corruption of file metadata and potential data loss or system inconsistencies.

Affected Systems

Linux kernel installations that enable the ext2 filesystem module are affected. The specific kernel versions containing the vulnerability are not disclosed in the CVE data, so any build that includes the ext2 module before the patch is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score of < 1 % and the absence from CISA’s KEV catalog suggest a low likelihood of widespread exploitation, and no evidence points to remote exploitation. The vulnerability is local, requiring an attacker to generate filesystem operations that modify an IS_SYNC inode. This finding is inferred from the description of the code path and the nature of the bug.

Generated by OpenCVE AI on September 15, 2026 at 21:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to the latest stable release that includes the ext2 patch
  • Reboot the system so the patched kernel and ext2 module are loaded
  • If an immediate upgrade is not possible, avoid marking critical inodes as IS_SYNC or migrate the data to a different filesystem until the patch can be applied

Generated by OpenCVE AI on September 15, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-821
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ext2: Fix lost inode updates for IS_SYNC inodes ext2_setsize() and ext2_xattr_set2() had a construct like: if (IS_SYNC(inode)) { sync_inode_metadata(inode, 1); } else { mark_inode_dirty(inode); } which leads to lost inode updates for IS_SYNC inodes because sync_inode_metadata() does anything only if the inode is already dirty and hence inode updates may be simply lost. Fix the problem by unconditionally marking the inode dirty and *then* call sync_inode_metadata().
Title ext2: Fix lost inode updates for IS_SYNC inodes
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:34.222Z

Reserved: 2026-09-11T19:38:34.732Z

Link: CVE-2026-89601

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:44.993

Modified: 2026-09-13T07:17:25.520

Link: CVE-2026-89601

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:04Z

Links: CVE-2026-89601 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses
  • CWE-821

    Incorrect Synchronization