---
id: CVE-2026-92487
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  exfat: fix valid_size extension over a shared writable mapping

  When a shared writable mapping has its valid_size extended by a buffered
  write or a page fault, exfat ze…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  exfat: fix valid_size extension over a shared writable mapping

  When a shared writable mapping has its valid_size extended by a buffered
  write or a page fault, exfat ze…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 82a81a7352bcf5f2756ac33d47ee0582737e9a85 <
    24f20986b253c3e4eb13ebe3c2007d1d352408a6
  - >-
    Linux >= 82a81a7352bcf5f2756ac33d47ee0582737e9a85 <
    1135704ed22f54873eb0498a232611d9eca30dd4
  - Linux 7.2
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:50.800'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92487'
references:
  - url: 'https://git.kernel.org/stable/c/1135704ed22f54873eb0498a232611d9eca30dd4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/24f20986b253c3e4eb13ebe3c2007d1d352408a6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.786Z'
epss: 0.00198
epssPercentile: 0.08513
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

exfat: fix valid_size extension over a shared writable mapping

When a shared writable mapping has its valid_size extended by a buffered
write or a page fault, exfat zeroes the page-cache gap below the new
valid_size. A store through the mapping can race with this zeroing and be
overwritten.

Fix this by zeroing the gap lazily. Drop ->map_pages so that every first
write fault goes through exfat_page_mkwrite(), which advances valid_size to
cover the faulting page. With fault-around enabled, a store could install a
writable PTE, skip ->page_mkwrite(), and land past valid_size without
advancing it. Extending valid_size one faulting page at a time also leaves
never-written pages in a large mapping alone.

The gap is filled with block granularity, zeroing only the not-uptodate
blocks and preserving blocks that may hold data stored through the mapping.
On the buffered-write path the invalidate lock is held and the gap is
unmapped before zeroing, so a racing store re-faults and, under the inode
lock, completes only after the gap has been zeroed and valid_size covers
it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
