Description
In the Linux kernel, the following vulnerability has been resolved:

ext4: fix buffer_head leak in ext4_init_orphan_info

ext4_init_orphan_info() reads orphan file blocks with ext4_bread()
and stores the returned buffer_head in oi->of_binfo[i].ob_bh.

If ext4_bread() succeeds but the orphan block magic or checksum
validation fails, the function jumps to out_free. However, the old
out_free loop starts releasing buffers from i - 1, so the current
buffer_head at index i is skipped.

This leaks the buffer_head reference obtained by ext4_bread() on the
bad magic and bad checksum error paths.

Fix this by tracking the number of successfully read buffer_heads and
releasing exactly those buffer_heads on the error path.
Published: 2026-09-17
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak
Action: Apply Patch
AI Analysis

Impact

The vulnerability is caused by failing to free a buffer_head returned by ext4_bread() when orphan block validation fails. The unused buffer_head reference is leaked, which can lead to a gradual increase in memory usage and may ultimately cause kernel pressure or instability. No remote code execution or privilege escalation is achieved; the impact is limited to resource exhaustion.

Affected Systems

All Linux systems running the Linux kernel before the patch that addresses ext4_init_orphan_info. The exact kernel release is not enumerated in the data, but any distribution shipping a kernel that contains the legacy implementation of ext4_init_orphan_info is affected. The vulnerability is vendor-agnostic within Linux.

Risk and Exploitability

The EPSS score of < 1% indicates that exploitation is highly unlikely. The vulnerability is not documented in CISA’s KEV catalog, and no public exploit is known. The CVSS score of 5.5 indicates a medium severity. Given the nature of the flaw—memory leaking rather than direct compromise—the risk to confidentiality, integrity, and availability is considered low. Attackers would need uninterrupted access to the system to notice the memory leak, making the attack vector unfeasible over typical attack windows.

Generated by OpenCVE AI on September 24, 2026 at 04:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the ext4_init_orphan_info buffer_head release fix.
  • If an immediate kernel upgrade is not available, apply the patch from the commit(s) referenced in the advisory URLs to the kernel source tree and rebuild the kernel.
  • Reboot the system after patching to ensure all memory references are released and the kernel runs the updated code.

Generated by OpenCVE AI on September 24, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 24 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 19 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ext4: fix buffer_head leak in ext4_init_orphan_info ext4_init_orphan_info() reads orphan file blocks with ext4_bread() and stores the returned buffer_head in oi->of_binfo[i].ob_bh. If ext4_bread() succeeds but the orphan block magic or checksum validation fails, the function jumps to out_free. However, the old out_free loop starts releasing buffers from i - 1, so the current buffer_head at index i is skipped. This leaks the buffer_head reference obtained by ext4_bread() on the bad magic and bad checksum error paths. Fix this by tracking the number of successfully read buffer_heads and releasing exactly those buffer_heads on the error path.
Title ext4: fix buffer_head leak in ext4_init_orphan_info
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:10.073Z

Reserved: 2026-09-16T12:21:13.871Z

Link: CVE-2026-92494

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:51.547

Modified: 2026-09-17T17:17:51.547

Link: CVE-2026-92494

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-17T00:00:00Z

Links: CVE-2026-92494 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T04:30:14Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime