PT-2026-90212 · Linux · Linux
CVE-2026-89496
·
Published
2026-09-11
·
Updated
2026-09-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: always run deallocs on copy-on-write completion
Local fuzzing of 6.12.94 has found the following memory leak
caused by doing 'copy file range()' within the same filesystem:
unreferenced object 0xffff88812192c980 (size 32):
comm "syz.0.49", pid 12095, jiffies 4294964143
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 00 00 00 00 00 00 00 ................
c0 c5 92 21 81 88 ff ff 00 02 00 00 00 06 00 00 ...!............
backtrace (crc 7068d63f):
kmemleak alloc recursive include/linux/kmemleak.h:42 [inline]
slab post alloc hook mm/slub.c:4152 [inline]
slab alloc node mm/slub.c:4197 [inline]
kmalloc cache noprof+0x168/0x2c0 mm/slub.c:4358
kmalloc noprof include/linux/slab.h:878 [inline]
ocfs2 find per slot free list fs/ocfs2/alloc.c:6618 [inline]
ocfs2 cache block dealloc+0x155/0x4b0 fs/ocfs2/alloc.c:6786
ocfs2 cache extent block free fs/ocfs2/alloc.c:6819 [inline]
ocfs2 unlink path+0x286/0x450 fs/ocfs2/alloc.c:2613
ocfs2 rotate subtree left fs/ocfs2/alloc.c:2779 [inline]
ocfs2 rotate tree left+0x1f6f/0x2da0 fs/ocfs2/alloc.c:2985
ocfs2 rotate tree left+0x283/0xe00 fs/ocfs2/alloc.c:3237
ocfs2 try to merge extent+0xf56/0x1a20 fs/ocfs2/alloc.c:3825
ocfs2 split extent+0x15f4/0x2940 fs/ocfs2/alloc.c:5138
ocfs2 clear ext refcount+0x2f6/0x550 fs/ocfs2/refcounttree.c:3098
ocfs2 replace clusters fs/ocfs2/refcounttree.c:3131 [inline]
ocfs2 make clusters writable fs/ocfs2/refcounttree.c:3255 [inline]
ocfs2 replace cow+0x991/0x1660 fs/ocfs2/refcounttree.c:3349
ocfs2 refcount cow hunk fs/ocfs2/refcounttree.c:3427 [inline]
ocfs2 refcount cow+0x5e1/0x9f0 fs/ocfs2/refcounttree.c:3470
ocfs2 prepare inode for write fs/ocfs2/file.c:2340 [inline]
ocfs2 file write iter+0xbda/0x1880 fs/ocfs2/file.c:2451
iter file splice write+0x890/0xf60 fs/splice.c:743
do splice from fs/splice.c:944 [inline]
direct splice actor+0x232/0x480 fs/splice.c:1167
splice direct to actor+0x4b4/0xb60 fs/splice.c:1111
do splice direct actor fs/splice.c:1210 [inline]
do splice direct+0x10f/0x1c0 fs/splice.c:1236
do sendfile+0x430/0xbf0 fs/read write.c:1388
unreferenced object 0xffff88812192c5c0 (size 32):
comm "syz.0.49", pid 12095, jiffies 4294964143
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
29 70 00 00 00 00 00 00 19 00 00 00 00 00 00 00 )p..............
backtrace (crc afec850f):
kmemleak alloc recursive include/linux/kmemleak.h:42 [inline]
slab post alloc hook mm/slub.c:4152 [inline]
slab alloc node mm/slub.c:4197 [inline]
kmalloc cache noprof+0x168/0x2c0 mm/slub.c:4358
kmalloc noprof include/linux/slab.h:878 [inline]
kzalloc noprof include/linux/slab.h:1014 [inline]
ocfs2 cache block dealloc+0x25c/0x4b0 fs/ocfs2/alloc.c:6793
ocfs2 cache extent block free fs/ocfs2/alloc.c:6819 [inline]
ocfs2 unlink path+0x286/0x450 fs/ocfs2/alloc.c:2613
ocfs2 rotate subtree left fs/ocfs2/alloc.c:2779 [inline]
ocfs2 rotate tree left+0x1f6f/0x2da0 fs/ocfs2/alloc.c:2985
ocfs2 rotate tree left+0x283/0xe00 fs/ocfs2/alloc.c:3237
ocfs2 try to merge extent+0xf56/0x1a20 fs/ocfs2/alloc.c:3825
ocfs2 split extent+0x15f4/0x2940 fs/ocfs2/alloc.c:5138
ocfs2 clear ext refcount+0x2f6/0x550 fs/ocfs2/refcounttree.c:3098
ocfs2 replace clusters fs/ocfs2/refcounttree.c:3131 [inline]
ocfs2 make clusters writable fs/ocfs2/refcounttree.c:3255 [inline]
ocfs2 replace cow+0x991/0x1660 fs/ocfs2/refcounttree.c:3349
ocfs2 refcount cow hunk fs/ocfs2/refcounttree.c:3427 [inline]
ocfs2 refcount cow+0x5e1/0x9f0 fs/ocfs2/refcounttree.c:3470
ocfs2 prepare inode for write fs/ocfs2/file.c:2340 [inline]
ocfs2 file write iter+0xbda/0x1880 fs/ocfs2/file.c:2451
iter file splice write+0x890/0xf60 fs/splice.c:743
do splice from fs/splice.c:9
---truncated---
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux