{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "82a81a7352bcf5f2756ac33d47ee0582737e9a85"
            },
            {
              "fixed": "24f20986b253c3e4eb13ebe3c2007d1d352408a6"
            },
            {
              "fixed": "1135704ed22f54873eb0498a232611d9eca30dd4"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "7.2.0"
            },
            {
              "fixed": "7.2.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92487.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix valid_size extension over a shared writable mapping\n\nWhen a shared writable mapping has its valid_size extended by a buffered\nwrite or a page fault, exfat zeroes the page-cache gap below the new\nvalid_size. A store through the mapping can race with this zeroing and be\noverwritten.\n\nFix this by zeroing the gap lazily. Drop -\u003emap_pages so that every first\nwrite fault goes through exfat_page_mkwrite(), which advances valid_size to\ncover the faulting page. With fault-around enabled, a store could install a\nwritable PTE, skip -\u003epage_mkwrite(), and land past valid_size without\nadvancing it. Extending valid_size one faulting page at a time also leaves\nnever-written pages in a large mapping alone.\n\nThe gap is filled with block granularity, zeroing only the not-uptodate\nblocks and preserving blocks that may hold data stored through the mapping.\nOn the buffered-write path the invalidate lock is held and the gap is\nunmapped before zeroing, so a racing store re-faults and, under the inode\nlock, completes only after the gap has been zeroed and valid_size covers\nit.",
  "id": "CVE-2026-92487",
  "modified": "2026-09-19T03:30:27.925615709Z",
  "published": "2026-09-17T16:10:02.317Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1135704ed22f54873eb0498a232611d9eca30dd4"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/24f20986b253c3e4eb13ebe3c2007d1d352408a6"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92487.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92487"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "exfat: fix valid_size extension over a shared writable mapping"
}