CVE-2026-72370

Source
https://cve.org/CVERecord?id=CVE-2026-72370
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72370.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72370
Downstream
Published
2026-08-15T05:56:06.648Z
Modified
2026-08-16T03:48:37.386401452Z
Summary
iomap: release pages on atomic dio size mismatch
Details

In the Linux kernel, the following vulnerability has been resolved:

iomap: release pages on atomic dio size mismatch

If bioiovitergetpages() or the bounce helper succeeds but builds a short bio, the REQ_ATOMIC size check rejects it before submission. The old error path only dropped the bio reference, leaving any pages already attached to the bio unreleased.

Release or unbounce the pages before falling through to outputbio on this error path.

This bug was reported by sashiko: https://sashiko.dev/#/patchset/20260608073134.95964-1-changfengnan%40bytedance.com

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72370.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9e0933c21c128d6d8ac4d8aae0babaf9a43100b8
Fixed
27ddd3442fc6f698fb8577c7cfb243ddd81ea8c0
Fixed
681e452683b69a8e1a571cba0f238f8ceacf55d2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72370.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72370.json"