CVE-2026-31514

Source
https://cve.org/CVERecord?id=CVE-2026-31514
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31514.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-31514
Downstream
Related
Published
2026-04-22T13:54:31Z
Modified
2026-08-27T18:26:13Z
Summary
erofs: set fileio bio failed in short read case
Details

In the Linux kernel, the following vulnerability has been resolved:

erofs: set fileio bio failed in short read case

For file-backed mount, IO requests are handled by vfs_iocb_iter_read(). However, it can be interrupted by SIGKILL, returning the number of bytes actually copied. Unused folios in bio are unexpectedly marked as uptodate.

vfs_read filemap_read filemap_get_pages filemap_readahead erofs_fileio_readahead erofs_fileio_rq_submit vfs_iocb_iter_read filemap_read filemap_get_pages <= detect signal erofs_fileio_ki_complete <= set all folios uptodate

This patch addresses this by setting short read bio with an error directly.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31514.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8d582d65d20bb4796db01b19e86909ad68cb337b
Fixed
d1ba7d6b3cd1757b108d7b6856c92ae661d6c323
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e49abde0ffc382a967b24f326d1614ac3bb06a94
Fixed
5cf3972c8221abdb1b464a14ccf8103d840b9085
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fe4039034dcdf584afbf763787909e28e92a4927
Fixed
5a5f23ef5431639db1ac3a0b274aef3a84cc413c
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bc804a8d7e865ef47fb7edcaf5e77d18bf444ebc
Fixed
eade54040384f54b7fb330e4b0975c5734850b3c

Affected versions

v6.*
v6.12.75
v6.12.76
v6.12.77
v6.12.78
v6.12.79
v6.18.14
v6.18.15
v6.18.16
v6.18.17
v6.18.18
v6.18.19
v6.18.20
v6.19.10
v6.19.4
v6.19.5
v6.19.6
v6.19.7
v6.19.8
v6.19.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31514.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.75
Fixed
6.12.80
Type
ECOSYSTEM
Events
Introduced
6.18.14
Fixed
6.18.21
Type
ECOSYSTEM
Events
Introduced
6.19.4
Fixed
6.19.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31514.json"