Impact
The bug is a race condition between direct I/O and the buffered write fallback path in the ext4 file system. An in‑flight direct I/O (DIO) can complete after the buffered write has dirtied pages but before the pages are flushed and invalidated. During that brief window, other kernel threads may invalidate the page cache, causing the buffered write path to detect a dirty page and trigger a warning that ultimately sets the error sequence to -EIO. The result is that fsync or subsequent writes can return a broken I/O error, and data written via DIO may be lost or corrupted. The flaw therefore threatens the confidentiality, integrity, and availability of data stored on ext4 volumes that use no‑extent inodes or participate in concurrent DIO requests.
Affected Systems
Any Linux system running the Linux kernel with the ext4 file system. The vulnerability affects all builds in which the ext4 code has not yet incorporated the patch that inserts an inode_dio_wait() call to drain outstanding DIO before dropping the inode lock, but specific version numbers are not disclosed. All Linux distributions using ext4 are potentially impacted unless they have applied the latest kernel fix.
Risk and Exploitability
EPSS is reported as less than 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in KEV. Based on the description, it is inferred that attacks would require local access to the affected machine to trigger concurrent DIO operations that race against the fallback path—for example, via a loop device or multiple threads performing direct I/O. The vulnerability arises in kernel code, so privileged access can broaden the impact, but even with standard user privileges, an attacker could cause fsync failures or data loss by inducing the race. Overall, the risk is moderate, mainly affecting reliability and data integrity rather than control takeover.
OpenCVE Enrichment
Debian DLA
Debian DSA