CVE-2026-92494

Source
https://cve.org/CVERecord?id=CVE-2026-92494
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92494.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92494
Downstream
Published
2026-09-17T16:10:10Z
Modified
2026-09-19T03:47:26Z
Summary
ext4: fix buffer_head leak in ext4_init_orphan_info
Details

In the Linux kernel, the following vulnerability has been resolved:

ext4: fix buffer_head leak in ext4_init_orphan_info

ext4_init_orphan_info() reads orphan file blocks with ext4_bread() and stores the returned buffer_head in oi->of_binfo[i].ob_bh.

If ext4_bread() succeeds but the orphan block magic or checksum validation fails, the function jumps to out_free. However, the old out_free loop starts releasing buffers from i - 1, so the current buffer_head at index i is skipped.

This leaks the buffer_head reference obtained by ext4_bread() on the bad magic and bad checksum error paths.

Fix this by tracking the number of successfully read buffer_heads and releasing exactly those buffer_heads on the error path.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92494.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
02f310fcf47fa9311d6ba2946a8d19e7d7d11f37
Fixed
a9a6ec1298f9bc134b2c5db27d25bb10603b7113
Fixed
35fc83c65faf7949f5701bb34b20f822560a7718
Fixed
74637f7fef030e5fb2e835b7dfeb05efdc48e0fe
Fixed
6ec53ccab0d691b3c73e03d930343ca45987e88d
Fixed
1399f102d8a1855c1a38506057306ec79d0787d9
Fixed
e1e342d9a561c016b8531ec1f4dcefaad9d64954
Fixed
05704335803b69c1bfa8637b7ada942bf2ee8a41

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92494.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92494.json"