rootpwn

high · CVSS v3 7.8

CVE-2026-93140

The CVE addresses a kernel bug where a write error to the UDF Logical Volume Integrity Descriptor (LVID) buffer clears the uptodate flag, ca

Overview

The CVE addresses a kernel bug where a write error to the UDF Logical Volume Integrity Descriptor (LVID) buffer clears the uptodate flag, causing a spurious WARN_ON_ONCE warning when the buffer is later marked dirty. The patch simply restores the flag before marking the buffer dirty, preventing the warning.

Description

In the Linux kernel, the following vulnerability has been resolved: udf: Mark LVID buffer as uptodate before marking it dirty When an I/O error occurs while writing the Logical Volume Integrity Descriptor (LVID) buffer to the block device, the block layer's completion handler (`end_buffer_write_sync()`) clears the `BH_Uptodate` flag on the buffer. However, the buffer still contains valid LVID data in memory. If the filesystem is subsequently remounted read-write or synced, `udf_open_lvid()` or `udf_sync_fs()` will modify the LVID buffer and call `mark_buffer_dirty()`. This triggers a spurious `WARN_ON_ONCE(!buffer_uptodate(bh))` warning in `mark_buffer_dirty()` because the buffer is not marked uptodate, even though its in-memory contents are valid and are about to be overwritten. To prevent this spurious warning, unconditionally set the `BH_Uptodate` flag before calling `mark_buffer_dirty()` in `udf_open_lvid()` and `udf_sync_fs()`. This acknowledges that the in-memory buffer is valid and matches the workaround previously applied to `udf_close_lvid()` in commit 853a0c25baf9 ("udf: Mark LVID buffer as uptodate before marking it dirty"). Extending this workaround ensures consistent behavior across all LVID updates. Buffer I/O error on dev loop0, logical block 128, lost sync page write ------------[ cut here ]------------ !buffer_uptodate(bh) WARNING: fs/buffer.c:1087 at mark_buffer_dirty+0x299/0x410 fs/buffer.c:1087 ... Call Trace: udf_open_lvid+0x369/0x5b0 fs/udf/super.c:2078 udf_reconfigure+0x336/0x540 fs/udf/super.c:679 reconfigure_super+0x232/0x8f0 fs/super.c:1080 vfs_cmd_reconfigure fs/fsopen.c:268 [inline] vfs_fsconfig_locked+0x171/0x320 fs/fsopen.c:297 __do_sys_fsconfig fs/fsopen.c:463 [inline] __se_sys_fsconfig+0x6b9/0x810 fs/fsopen.c:350 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94

Impact

This issue does not compromise confidentiality, integrity, or availability. It can lead to noisy kernel logs and, in rare cases, kernel instability if the warning triggers a panic or if repeated errors accumulate. Defenders should treat it as a kernel reliability issue rather than a security flaw.

Remediation

Apply the latest kernel update that includes the UDF LVID buffer uptodate flag fix (e.g., any kernel release after the commit that added the workaround). If an immediate update is not possible, monitor dmesg and syslog for repeated `!buffer_uptodate(bh)` warnings and consider temporarily disabling UDF mounts or using a different filesystem until the patch is applied.

Risk context

The CVSS score of 7.8 reflects the potential for kernel instability rather than a direct exploit. The EPSS is not available, but the high severity indicates that the issue should be addressed promptly to maintain system reliability.

Affected products

  • Linux kernel

Scores

Severity
high
CVSS v2
6.8
CVSS v3
7.8
CVSS v4
EPSS

linux kernel udf buffer flag kernel warning patch monitoring reliability

← All CVEs