CVE-2026-74308
CVE CVE-2026-74308EUVD EUVD-2026-59455Published 2026-08-15T05:58:08.000ZLast changed 2026-08-17T05:16:57.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ext4: fix kernel BUG in ext4_write_inline_data_end When the data=journal mount option is used, the ext4_journalled_write_end() function incorrectly calls ext4_write_inline_data_end() without checking if the EXT4_STATE_MAY_INLINE_DATA flag is still set on the inode. If a previous attempt to convert the inline data to an extent failed (e.g. due to ENOSPC), the EXT4_STATE_MAY_INLINE_DATA flag is cleared, but the EXT4_INODE_INLINE_DATA flag remains set. In this scenario, the next call to ext4_write_begin() will not prepare the inline data xattr for writing, but ext4_journalled_write_end() will incorrectly attempt to write to it, triggering a BUG_ON(pos + len > EXT4_I(inode)->i_inline_size) in ext4_write_inline_data() since i_inline_size was not expanded. Fix this by ensuring that ext4_journalled_write_end() only calls ext4_write_inline_data_end() if the EXT4_STATE_MAY_INLINE_DATA flag is set, mirroring the behavior of ext4_write_end() and ext4_da_write_end().
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb <9808ae9fae996afa942bd963a39c9b1cdeebd0bd; patch: 6.12.97; 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb <f00f5c0dd55319bc33b76f72c853bda0e0a32eda; patch: 7.1.5; 3.8; 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb <ad09aa45965d3fafaf9963bc78109b73c0f9ac8d; patch: 7.2; patch: 6.6.145; 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb <260830a9a706f5d335398236fc788ce32f220de1; patch: 6.18.40; patch: 0; 3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb <0ae42b51607240990614e0843f0d3529aaff62cc
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.