← Back to CVE search

CVE-2026-31448

Linux Kernel

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if inserting a new extent into the extent tree fails (in this example, because the file system disabled the huge file feature when marking the inode as dirty), ext4_ext_map_blocks() only calls ext4_free_blocks() to reclaim the physical block without deleting the corresponding data in the extent tree. This causes subsequent mkdir operations to reference the previously reclaimed physical block number again, even though this physical block is already being used by the xattr block. Therefore, a situation arises where both the directory and xattr are using the same buffer head block in memory simultaneously. The above causes ext4_xattr_block_set() to enter an infinite loop about -inserted- and cannot release the inode lock, ultimately leading to the 143s blocking problem mentioned in [1]. If the metada...

CVSS 9.4EPSS 0.443%Risk 0.98
View source
Published
2026-04-22 14:16:38
Affected versions
unknown
Type
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Operating systems
Linux