{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "dff4ac75eeeefc4397fe7cf8ce559425bf46b1f7"
            },
            {
              "fixed": "f82a4929d0ef7ddf254c1c295ec1dfd24094f2de"
            },
            {
              "fixed": "a450ab88bfd57b227d72c7a3faad54d16c3fc099"
            },
            {
              "fixed": "aa0042630b1f7cab735b0a168539281198822586"
            },
            {
              "fixed": "43ae387c3ae6a11227d096669ddf883e27a39a11"
            },
            {
              "fixed": "ec524aae479b4b2078c47492b90ec21200bce434"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.157"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.110"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.52"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92502.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: clear stale xarray tags on folios skipped during writeback\n\nIn data=journal mode, the writeback thread can hit the\nWARN_ON_ONCE(sb_rdonly(sb)) in ext4_journal_check_start() while the\nsuperblock is being remounted read-only during reboot:\n\nWorkqueue: writeback wb_workfn (flush-253:0)\nRIP: 0010:ext4_journal_check_start+0x8b/0xd0\nCall Trace:\n  __ext4_journal_start_sb+0x3c/0x1e0\n  mpage_prepare_extent_to_map+0x4af/0x580\n  ext4_do_writepages+0x3c0/0x1080\n  ext4_writepages+0xc8/0x1a0\n  do_writepages+0xc4/0x180\n  __writeback_single_inode+0x45/0x2f0\n  writeback_sb_inodes+0x26b/0x5d0\n  __writeback_inodes_wb+0x54/0x100\n  wb_writeback+0x1ac/0x320\n  wb_workfn+0x394/0x470\n\nAnd followed by the warning:\nEXT4-fs warning (device vda1): ext4_evict_inode:195: inode #6263:\ncomm (sd-umount): data will be lost\n\nThis issue is not reproduced every time, but frequently.\nThe reproduction step is to create a VM with 8 CPUs, 16G memory and\nsetup data=journal:\nsudo tune2fs -o journal_data /dev/vda1\nRun fio:\nrm -f fiotest\nfio --name=fiotest --rw=randwrite --bs=4k --runtime=6 --ioengine=libaio\n--iodepth=256 --numjobs=8 --filename=fiotest --filesize=30G\n--group_reporting\nReboot the VM, and check the console output from:\nvirsh console testvm\n\nBut there is no dirty inode, folio_clear_dirty_for_io clears PG_dirty\nbut leaves tags PAGECACHE_TAG_DIRTY and PAGECACHE_TAG_TOWRITE set which\nare only cleared by __folio_start_writeback.\nIn data=journal mode, jbd2 checkpoints the journalled data to its final\nlocation and clears its own dirty flag without touching folio PG_dirty\nor xarray dirty flags.\nThe commit f4a2b42e7891 (\"ext4: fix stale xarray tags after writeback\")\nfixes when PG_dirty is still set but there is no dirty page.\nAnother case is PG_dirty is cleared, but PAGECACHE_TAG_DIRTY and\nPAGECACHE_TAG_TOWRITE is still set. In this case, writeback thread\nchecks clean folio and skips it in mpage_prepare_extent_to_map:\nif (!folio_test_dirty(folio) ||\n    ...\n        folio_unlcok(folio);\n\tcontinue\n\nAnd never reaches ext4_bio_write_folio where the commit f4a2b42e7891\nclears the stale xarray tags. Print debug logs after the filesystem\nis remounted read-only:\nwritepages RDONLY nrpages=2048 dirtytag=1 wbtag=0 towrite=1 sync=0\nAnd all folios are actually clean:\nfolio idx=3 dirty=0 wb=0 checked=0 dirtybuf=0 jbddirty=0 mapped=1\n...\n\nWe need to clear the xarray stale tags for such clean folios by\ncycling them through writeback in the skip path, the same way\nf4a2b42e7891 does in ext4_bio_write_folio.",
  "id": "CVE-2026-92502",
  "modified": "2026-09-19T03:30:15.100904098Z",
  "published": "2026-09-17T16:10:15.399Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/43ae387c3ae6a11227d096669ddf883e27a39a11"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a450ab88bfd57b227d72c7a3faad54d16c3fc099"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/aa0042630b1f7cab735b0a168539281198822586"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ec524aae479b4b2078c47492b90ec21200bce434"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/f82a4929d0ef7ddf254c1c295ec1dfd24094f2de"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92502.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92502"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "ext4: clear stale xarray tags on folios skipped during writeback"
}