Impact
In the ext2 filesystem code of the Linux kernel, functions that set inode size or extended attributes used a pattern that only called sync_inode_metadata when the inode was already dirty. When an inode was marked with the IS_SYNC flag, this check caused any metadata writes to that inode to be lost because sync_inode_metadata alone does nothing unless the inode is dirty. Consequently, updates to the inode’s metadata could vanish, leading to corruption of file metadata and potential data loss or system inconsistencies.
Affected Systems
Linux kernel installations that enable the ext2 filesystem module are affected. The specific kernel versions containing the vulnerability are not disclosed in the CVE data, so any build that includes the ext2 module before the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of < 1 % and the absence from CISA’s KEV catalog suggest a low likelihood of widespread exploitation, and no evidence points to remote exploitation. The vulnerability is local, requiring an attacker to generate filesystem operations that modify an IS_SYNC inode. This finding is inferred from the description of the code path and the nature of the bug.
OpenCVE Enrichment