Impact
This vulnerability originates in the Linux kernel’s ext4 filesystem writeback logic. When ext4 is operating in journal_data mode and a reboot occurs, the writeback thread may encounter a stale set of dirty flags on cached page frames (folios). The kernel fails to clear these flags, causing the system to emit warnings and potentially lose data during the remount of the filesystem. The flaw does not constitute an arbitrary code execution vector, but it undermines the correctness of filesystem state and can result in loss of written data.
Affected Systems
All installations of the Linux kernel that use the ext4 filesystem and enable the journal_data mode are affected. The issue is tied to the underlying kernel code referenced by the ciphered identifiers in the description; it does not depend on a specific kernel version beyond the presence of the bug. Users must verify which kernel branch contains the f4a2b42e7891 fix before applying an update.
Risk and Exploitability
The EPSS score of less than 1% indicates that, while the defect exists, it is considered unlikely to be widely exploited in the short term. The vulnerability is not in the CISA KEV catalog, and it does not provide an attacker with direct control over the system. However, if the conditions described are met—a heavy I/O workload, journal_data mode, and a reboot—file integrity may be compromised. Operators should treat this as a data integrity risk that can be mitigated by updating to a kernel that includes the patch that corrects stale xarray tag handling.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN