CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount
Published Apr 22, 2026
·Updated
ext4: fix use-after-free in updatesuperwork when racing with umount
Affected Software
21 affected componentsFixes available
Linux Linux kernel (ext4)
Microsoft azl3 kernel 6.6.130.1-3
Linux Linux kernel>=5.10.114<5.11
Linux Linux kernel>=5.15.38<5.15.203
Linux Linux kernel>=5.17.6<5.18
Linux Linux kernel>=5.18.1<6.1.168
Linux Linux kernel>=6.2<6.6.131
Linux Linux kernel>=6.7<6.12.80
Linux Linux kernel>=6.13<6.18.21
Linux Linux kernel>=6.19<6.19.11
Linux Linux kernel=5.18
Linux Linux kernel=5.18-rc4
Linux Linux kernel=5.18-rc5
Linux Linux kernel=5.18-rc6
Linux Linux kernel=5.18-rc7
Linux Linux kernel=5.18-rc9
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Event History
Apr 22, 2026
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
DescriptionSeverity
Data Sourced
via NVD·02:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 23, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:06 AM
Affected Software
Updated
via Microsoft·08:06 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-31446?
The severity of CVE-2026-31446 is high, with a score of 7.8.
2
What is CVE-2026-31446 about?
CVE-2026-31446 addresses a use-after-free vulnerability in the ext4 filesystem when racing with the umount operation.
3
How do I fix CVE-2026-31446?
To fix CVE-2026-31446, apply the available patch from the Linux kernel updates.
4
Which software is affected by CVE-2026-31446?
CVE-2026-31446 affects the Linux kernel, specifically the ext4 filesystem.
5
What are the consequences of exploiting CVE-2026-31446?
Exploiting CVE-2026-31446 may lead to elevated privileges and could compromise confidentiality, integrity, and availability.