CVE-2026-45899: ext4: drop extent cache when splitting extent fails
In the Linux kernel, the following vulnerability has been resolved:
ext4: drop extent cache when splitting extent fails
When the split extent fails, we might leave some extents still being processed and return an error directly, which will result in stale extent entries remaining in the extent status tree. So drop all of the remaining potentially stale extents if the splitting fails.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45899?
CVE-2026-45899 has a critical severity rating of 9.8.
How do I fix CVE-2026-45899?
To fix CVE-2026-45899, update your Linux kernel to a version that includes the patch for this vulnerability.
What type of access is required to exploit CVE-2026-45899?
CVE-2026-45899 requires an attacker to have network access.
What are the consequences of CVE-2026-45899?
Exploitation of CVE-2026-45899 can lead to data corruption due to stale extent entries remaining in the extent status cache.
Which software is affected by CVE-2026-45899?
CVE-2026-45899 affects the ext4 filesystem in the Linux kernel and Microsoft azl3 kernel 6.6.139.1-1.