{"id":"CVE-2026-92502","title":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: clear stale xarray tags on folios skipped during writeback\n\nIn data=journal mode, the writeback thread can hit the\nWARN_ON_ONCE(sb_rdonly(sb)) in ext4_journal_che…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: clear stale xarray tags on folios skipped during writeback\n\nIn data=journal mode, the writeback thread can hit the\nWARN_ON_ONCE(sb_rdonly(sb)) in ext4_journal_che…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= dff4ac75eeeefc4397fe7cf8ce559425bf46b1f7 < f82a4929d0ef7ddf254c1c295ec1dfd24094f2de","Linux >= dff4ac75eeeefc4397fe7cf8ce559425bf46b1f7 < a450ab88bfd57b227d72c7a3faad54d16c3fc099","Linux >= dff4ac75eeeefc4397fe7cf8ce559425bf46b1f7 < aa0042630b1f7cab735b0a168539281198822586","Linux >= dff4ac75eeeefc4397fe7cf8ce559425bf46b1f7 < 43ae387c3ae6a11227d096669ddf883e27a39a11","Linux >= dff4ac75eeeefc4397fe7cf8ce559425bf46b1f7 < ec524aae479b4b2078c47492b90ec21200bce434","Linux 6.2"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:52.680","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92502","references":[{"url":"https://git.kernel.org/stable/c/43ae387c3ae6a11227d096669ddf883e27a39a11","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a450ab88bfd57b227d72c7a3faad54d16c3fc099","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa0042630b1f7cab735b0a168539281198822586","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec524aae479b4b2078c47492b90ec21200bce434","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f82a4929d0ef7ddf254c1c295ec1dfd24094f2de","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.783Z","epss":0.00168,"epssPercentile":0.06442,"slug":"CVE-2026-92502","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\next4: clear stale xarray tags on folios skipped during writeback\n\nIn data=journal mode, the writeback thread can hit the\nWARN_ON_ONCE(sb_rdonly(sb)) in ext4_journal_check_start() while the\nsuperblock is being remounted read-only during reboot:\n\nWorkqueue: writeback wb_workfn (flush-253:0)\nRIP: 0010:ext4_journal_check_start+0x8b/0xd0\nCall Trace:\n  __ext4_journal_start_sb+0x3c/0x1e0\n  mpage_prepare_extent_to_map+0x4af/0x580\n  ext4_do_writepages+0x3c0/0x1080\n  ext4_writepages+0xc8/0x1a0\n  do_writepages+0xc4/0x180\n  __writeback_single_inode+0x45/0x2f0\n  writeback_sb_inodes+0x26b/0x5d0\n  __writeback_inodes_wb+0x54/0x100\n  wb_writeback+0x1ac/0x320\n  wb_workfn+0x394/0x470\n\nAnd followed by the warning:\nEXT4-fs warning (device vda1): ext4_evict_inode:195: inode #6263:\ncomm (sd-umount): data will be lost\n\nThis issue is not reproduced every time, but frequently.\nThe reproduction step is to create a VM with 8 CPUs, 16G memory and\nsetup data=journal:\nsudo tune2fs -o journal_data /dev/vda1\nRun fio:\nrm -f fiotest\nfio --name=fiotest --rw=randwrite --bs=4k --runtime=6 --ioengine=libaio\n--iodepth=256 --numjobs=8 --filename=fiotest --filesize=30G\n--group_reporting\nReboot the VM, and check the console output from:\nvirsh console testvm\n\nBut there is no dirty inode, folio_clear_dirty_for_io clears PG_dirty\nbut leaves tags PAGECACHE_TAG_DIRTY and PAGECACHE_TAG_TOWRITE set which\nare only cleared by __folio_start_writeback.\nIn data=journal mode, jbd2 checkpoints the journalled data to its final\nlocation and clears its own dirty flag without touching folio PG_dirty\nor xarray dirty flags.\nThe commit f4a2b42e7891 (\"ext4: fix stale xarray tags after writeback\")\nfixes when PG_dirty is still set but there is no dirty page.\nAnother case is PG_dirty is cleared, but PAGECACHE_TAG_DIRTY and\nPAGECACHE_TAG_TOWRITE is still set. In this case, writeback thread\nchecks clean folio and skips it in mpage_prepare_extent_to_map:\nif (!folio_test_dirty(folio) ||\n    ...\n        folio_unlcok(folio);\n\tcontinue\n\nAnd never reaches ext4_bio_write_folio where the commit f4a2b42e7891\nclears the stale xarray tags. Print debug logs after the filesystem\nis remounted read-only:\nwritepages RDONLY nrpages=2048 dirtytag=1 wbtag=0 towrite=1 sync=0\nAnd all folios are actually clean:\nfolio idx=3 dirty=0 wb=0 checked=0 dirtybuf=0 jbddirty=0 mapped=1\n...\n\nWe need to clear the xarray stale tags for such clean folios by\ncycling them through writeback in the skip path, the same way\nf4a2b42e7891 does in ext4_bio_write_folio.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}