CVE-2026-45984CWE-416CWE-826

CVE-2026-45984

High · published May 27, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
8.1
In the wild
Unconfirmed
What it is

In the Linux kernel, the following vulnerability has been resolved:

gfs2: Fix use-after-free in iomap inline data write path

The inline data buffer head (dibh) is being released prematurely in

gfs2_iomap_begin() via release_metapath() while iomap->inline_data

still points to dibh->b_data. This causes a use-after-free when

iomap_write_end_inline() later attempts to write to the inline data

area.

The bug sequence:

1. gfs2_iomap_begin() calls gfs2_meta_inode_buffer() to read inode

metadata into dibh

2. Sets iomap->inline_data = dibh->b_data + sizeof(struct gfs2_dinode)

3. Calls release_metapath() which calls brelse(dibh), dropping refcount

to 0

4. kswapd reclaims the page (~39ms later in the syzbot report)

5. iomap_write_end_inline() tries to memcpy() to iomap->inline_data

6. KASAN detects use-after-free write to freed memory

Fix by storing dibh in iomap->private and incrementing its refcount

with get_bh() in gfs2_iomap_begin(). The buffer is then properly

released in gfs2_iomap_end() after the inline write completes,

ensuring the page stays alive for the entire iomap operation.

Note: A C reproducer is not available for this issue. The fix is based

on analysis of the KASAN report and code review showing the buffer head

is freed before use.

[agruenba: Take buffer head reference in gfs2_iomap_begin() to avoid

leaks in gfs2_iomap_get() and gfs2_iomap_alloc().]

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00184 · 8.1th percentile
Weaknesses
CWE-416 · Use After Free; CWE-826 · Premature Release of Resource During Expected Lifetime
Published
2026-05-27T18:17Z
Affected products (7)
ProductVersionsFixed in
linux/linux_kernel≥ 5.2, < 5.10.2525.10.252
linux/linux_kernel≥ 5.11, < 5.15.2025.15.202
linux/linux_kernel≥ 5.16, < 6.1.1656.1.165
linux/linux_kernel≥ 6.2, < 6.6.1286.6.128
linux/linux_kernel≥ 6.7, < 6.12.756.12.75
linux/linux_kernel≥ 6.13, < 6.18.146.18.14
linux/linux_kernel≥ 6.19, < 6.19.46.19.4
References (29)
https://git.kernel.org/stable/c/1403989d1b502f4a2c0d0b42ccf1c25748442eff · 416baaa9-dc9f-4396-8d5f-8c081fb06d67https://git.kernel.org/stable/c/1cae1bafdf9caa9b462b19af06b1a06902e4e142 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67https://git.kernel.org/stable/c/6d76febba07c40bcf358f63216d36ea68cf1c215 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67https://git.kernel.org/stable/c/764c3c84b5683e608f43735c803a5f415046686c · 416baaa9-dc9f-4396-8d5f-8c081fb06d67https://git.kernel.org/stable/c/815ddd27c0c7171a99fe802fdb19098ddef8b19d · 416baaa9-dc9f-4396-8d5f-8c081fb06d67https://git.kernel.org/stable/c/87d4954b5c59735a99ea98cb208d47130f6dce7d · 416baaa9-dc9f-4396-8d5f-8c081fb06d67https://git.kernel.org/stable/c/d87268326b277af3665237ac76a73dd9fa8e21b4 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67https://git.kernel.org/stable/c/faddeb848305e79db89ee0479bb0e33380656321 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67https://access.redhat.com/errata/RHSA-2026:27789 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33743 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:35894 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:36049 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:36767 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:38902 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:51603 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:51604 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:55444 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:59142 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:59143 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:59145 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:59146 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:59147 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:59148 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:59149 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:61692 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:63189 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/security/cve/CVE-2026-45984 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://bugzilla.redhat.com/show_bug.cgi?id=2481922 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45984.json · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
EPSS history
Timeline
  • 27 MAY 12:18Z
    gfs2: Fix use-after-free in iomap inline data write path
    cvelistv5