PT-2026-90212 · Linux · Linux

CVE-2026-89496

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: always run deallocs on copy-on-write completion
Local fuzzing of 6.12.94 has found the following memory leak caused by doing 'copy file range()' within the same filesystem:
unreferenced object 0xffff88812192c980 (size 32): comm "syz.0.49", pid 12095, jiffies 4294964143 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 08 00 00 00 00 00 00 00 ................ c0 c5 92 21 81 88 ff ff 00 02 00 00 00 06 00 00 ...!............ backtrace (crc 7068d63f): kmemleak alloc recursive include/linux/kmemleak.h:42 [inline] slab post alloc hook mm/slub.c:4152 [inline] slab alloc node mm/slub.c:4197 [inline] kmalloc cache noprof+0x168/0x2c0 mm/slub.c:4358 kmalloc noprof include/linux/slab.h:878 [inline] ocfs2 find per slot free list fs/ocfs2/alloc.c:6618 [inline] ocfs2 cache block dealloc+0x155/0x4b0 fs/ocfs2/alloc.c:6786 ocfs2 cache extent block free fs/ocfs2/alloc.c:6819 [inline] ocfs2 unlink path+0x286/0x450 fs/ocfs2/alloc.c:2613 ocfs2 rotate subtree left fs/ocfs2/alloc.c:2779 [inline] ocfs2 rotate tree left+0x1f6f/0x2da0 fs/ocfs2/alloc.c:2985 ocfs2 rotate tree left+0x283/0xe00 fs/ocfs2/alloc.c:3237 ocfs2 try to merge extent+0xf56/0x1a20 fs/ocfs2/alloc.c:3825 ocfs2 split extent+0x15f4/0x2940 fs/ocfs2/alloc.c:5138 ocfs2 clear ext refcount+0x2f6/0x550 fs/ocfs2/refcounttree.c:3098 ocfs2 replace clusters fs/ocfs2/refcounttree.c:3131 [inline] ocfs2 make clusters writable fs/ocfs2/refcounttree.c:3255 [inline] ocfs2 replace cow+0x991/0x1660 fs/ocfs2/refcounttree.c:3349 ocfs2 refcount cow hunk fs/ocfs2/refcounttree.c:3427 [inline] ocfs2 refcount cow+0x5e1/0x9f0 fs/ocfs2/refcounttree.c:3470 ocfs2 prepare inode for write fs/ocfs2/file.c:2340 [inline] ocfs2 file write iter+0xbda/0x1880 fs/ocfs2/file.c:2451 iter file splice write+0x890/0xf60 fs/splice.c:743 do splice from fs/splice.c:944 [inline] direct splice actor+0x232/0x480 fs/splice.c:1167 splice direct to actor+0x4b4/0xb60 fs/splice.c:1111 do splice direct actor fs/splice.c:1210 [inline] do splice direct+0x10f/0x1c0 fs/splice.c:1236 do sendfile+0x430/0xbf0 fs/read write.c:1388
unreferenced object 0xffff88812192c5c0 (size 32): comm "syz.0.49", pid 12095, jiffies 4294964143 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 29 70 00 00 00 00 00 00 19 00 00 00 00 00 00 00 )p.............. backtrace (crc afec850f): kmemleak alloc recursive include/linux/kmemleak.h:42 [inline] slab post alloc hook mm/slub.c:4152 [inline] slab alloc node mm/slub.c:4197 [inline] kmalloc cache noprof+0x168/0x2c0 mm/slub.c:4358 kmalloc noprof include/linux/slab.h:878 [inline] kzalloc noprof include/linux/slab.h:1014 [inline] ocfs2 cache block dealloc+0x25c/0x4b0 fs/ocfs2/alloc.c:6793 ocfs2 cache extent block free fs/ocfs2/alloc.c:6819 [inline] ocfs2 unlink path+0x286/0x450 fs/ocfs2/alloc.c:2613 ocfs2 rotate subtree left fs/ocfs2/alloc.c:2779 [inline] ocfs2 rotate tree left+0x1f6f/0x2da0 fs/ocfs2/alloc.c:2985 ocfs2 rotate tree left+0x283/0xe00 fs/ocfs2/alloc.c:3237 ocfs2 try to merge extent+0xf56/0x1a20 fs/ocfs2/alloc.c:3825 ocfs2 split extent+0x15f4/0x2940 fs/ocfs2/alloc.c:5138 ocfs2 clear ext refcount+0x2f6/0x550 fs/ocfs2/refcounttree.c:3098 ocfs2 replace clusters fs/ocfs2/refcounttree.c:3131 [inline] ocfs2 make clusters writable fs/ocfs2/refcounttree.c:3255 [inline] ocfs2 replace cow+0x991/0x1660 fs/ocfs2/refcounttree.c:3349 ocfs2 refcount cow hunk fs/ocfs2/refcounttree.c:3427 [inline] ocfs2 refcount cow+0x5e1/0x9f0 fs/ocfs2/refcounttree.c:3470 ocfs2 prepare inode for write fs/ocfs2/file.c:2340 [inline] ocfs2 file write iter+0xbda/0x1880 fs/ocfs2/file.c:2451 iter file splice write+0x890/0xf60 fs/splice.c:743 do splice from fs/splice.c:9 ---truncated---
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89496

Affected Products

Linux