---
id: CVE-2026-92501
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ext4: drain in-flight DIO before buffered write fallback

  generic/746 started failing intermittently on ext3 (no-extent inodes).
  The test triggers 'Page cache invalidat…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ext4: drain in-flight DIO before buffered write fallback

  generic/746 started failing intermittently on ext3 (no-extent inodes).
  The test triggers 'Page cache invalidat…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 378f32bab3714f04c4e0c3aee4129f6703805550 <
    fd7e0dab20837b9ea1eeef7c26f78ace8ac8258c
  - >-
    Linux >= 378f32bab3714f04c4e0c3aee4129f6703805550 <
    f0af3ae09fb72382da1a5371bf6761b0264668e4
  - >-
    Linux >= 378f32bab3714f04c4e0c3aee4129f6703805550 <
    7341e234927ff215f1d5d0bcfe04b74f53af378d
  - >-
    Linux >= 378f32bab3714f04c4e0c3aee4129f6703805550 <
    74eee4ff9698a65b2e6e15dac0e50d6526ad5f20
  - >-
    Linux >= 378f32bab3714f04c4e0c3aee4129f6703805550 <
    d47cdadd6e49023f7ee248048463807f1214f1ee
  - >-
    Linux >= 378f32bab3714f04c4e0c3aee4129f6703805550 <
    4e4e3eec506247c8f8bd8aaa1eb25e67016681a5
  - >-
    Linux >= 378f32bab3714f04c4e0c3aee4129f6703805550 <
    9fd3ffc3c51c9deaba99bd7b338fff2d08f52416
  - >-
    Linux >= 378f32bab3714f04c4e0c3aee4129f6703805550 <
    15cdefd0c0522f9d5e12d947fa04f4c11649b699
  - Linux 5.5
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:52.517'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92501'
references:
  - url: 'https://git.kernel.org/stable/c/15cdefd0c0522f9d5e12d947fa04f4c11649b699'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4e4e3eec506247c8f8bd8aaa1eb25e67016681a5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7341e234927ff215f1d5d0bcfe04b74f53af378d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/74eee4ff9698a65b2e6e15dac0e50d6526ad5f20'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9fd3ffc3c51c9deaba99bd7b338fff2d08f52416'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d47cdadd6e49023f7ee248048463807f1214f1ee'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f0af3ae09fb72382da1a5371bf6761b0264668e4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fd7e0dab20837b9ea1eeef7c26f78ace8ac8258c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.782Z'
epss: 0.00177
epssPercentile: 0.07462
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ext4: drain in-flight DIO before buffered write fallback

generic/746 started failing intermittently on ext3 (no-extent inodes).
The test triggers 'Page cache invalidation failure on direct I/O'
warnings and subsequent fsync returns -EIO. Adding a 50ms delay
between ext4_buffered_write_iter() and filemap_write_and_wait_range()
in ext4_dio_write_iter() makes the race almost always reproducible.

On no-extent inodes, DIO writes to holes cannot use unwritten extents,
so ext4_iomap_alloc() leaves m_flags=0 and ext4_map_blocks() returns 0.
The iomap layer then returns -ENOTBLK, causing fallback to buffered I/O.

The fallback path in ext4_dio_write_iter() calls
ext4_buffered_write_iter() which dirties pages, then does flush and
invalidate. However, there's an unprotected window between
ext4_buffered_write_iter() returning (with inode lock released) and
the subsequent flush+invalidate.

Concurrent async DIO completions from other threads can run
kiocb_invalidate_post_direct_write() during this window. If pages have
been re-dirtied, post-invalidation finds dirty pages and triggers the
warning, setting -EIO in the error sequence.

Consider a file with two 4k extents: [hole][written]. Thread A does
DIO to the written extent, while thread B does DIO spanning both:

  kworker A (4k DIO, allocated block)    kworker B (8k DIO, fallback)
  -----------------------------------    ----------------------------
  inode_lock_shared()                    inode_lock_shared()
  iomap_dio_rw():                        iomap_dio_rw():
    kiocb_invalidate_pages -> clean        iomap_begin -> -ENOTBLK
    submit_bio (async)                     dio->size = 0
  inode_unlock_shared()                  inode_unlock_shared()

  [bio pending in block layer]           /* fallback: lock released */
                                         ext4_buffered_write_iter()
                                           inode_lock(exclusive)
                                           generic_perform_write()
                                             -> dirty pages [0, 8k]
                                           inode_unlock(exclusive)

                                         /* pages dirty, no lock */
  [bio completes]                        filemap_write_and_wait_range()
  iomap_dio_complete()                     -> flush dirty pages
    kiocb_invalidate_post_direct_write() invalidate_mapping_pages()
      invalidate_inode_pages2_range()
      -> finds dirty page!
      -> dio_warn_stale_pagecache()
      -> errseq_set(-EIO)

This issue can be triggered through normal I/O paths, not just
intentionally overlapping DIO writes from userspace. For example,
generic/746 uses a loop device where multiple kworkers issue concurrent
I/O to the backing file. Additionally, when block_size < folio_size,
non-overlapping DIO writes that share a large folio can also trigger
the race.

Add inode_dio_wait() in ext4_buffered_write_iter() before
ext4_write_checks() to drain all in-flight DIO. This ensures that
all DIO clears existing pages before submitting IO (via
kiocb_invalidate_pages()), all BIO waits for all DIO to complete
(via inode_dio_wait()), and ext4_write_checks() observes the inode
size after all completed DIO so that ext4_block_zero_eof() does not
race with in-flight DIO, thus eliminating the race.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
