Description
In the Linux kernel, the following vulnerability has been resolved:

gfs2: Fix use-after-free in iomap inline data write path

The inline data buffer head (dibh) is being released prematurely in
gfs2_iomap_begin() via release_metapath() while iomap->inline_data
still points to dibh->b_data. This causes a use-after-free when
iomap_write_end_inline() later attempts to write to the inline data
area.

The bug sequence:
1. gfs2_iomap_begin() calls gfs2_meta_inode_buffer() to read inode
metadata into dibh
2. Sets iomap->inline_data = dibh->b_data + sizeof(struct gfs2_dinode)
3. Calls release_metapath() which calls brelse(dibh), dropping refcount
to 0
4. kswapd reclaims the page (~39ms later in the syzbot report)
5. iomap_write_end_inline() tries to memcpy() to iomap->inline_data
6. KASAN detects use-after-free write to freed memory

Fix by storing dibh in iomap->private and incrementing its refcount
with get_bh() in gfs2_iomap_begin(). The buffer is then properly
released in gfs2_iomap_end() after the inline write completes,
ensuring the page stays alive for the entire iomap operation.

Note: A C reproducer is not available for this issue. The fix is based
on analysis of the KASAN report and code review showing the buffer head
is freed before use.

[agruenba: Take buffer head reference in gfs2_iomap_begin() to avoid
leaks in gfs2_iomap_get() and gfs2_iomap_alloc().]
Published: 2026-05-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4606-1 linux security update
Ubuntu USN Ubuntu USN USN-8492-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8497-1 Linux kernel (Low Latency) vulnerabilities
Ubuntu USN Ubuntu USN USN-8498-1 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8499-1 Linux kernel (Xilinx) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-3 Linux kernel (Raspberry Pi Real-time) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-4 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-5 Linux kernel (FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8575-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8576-1 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8575-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8576-2 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8597-1 Linux kernel (IBM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8575-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8606-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8607-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8609-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8610-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8619-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8620-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8620-2 Linux kernel (Azure FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8620-3 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-8620-4 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-8668-1 Linux kernel (GCP) vulnerabilities
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:27789 cve-icon
https://access.redhat.com/errata/RHSA-2026:33743 cve-icon
https://access.redhat.com/errata/RHSA-2026:35894 cve-icon
https://access.redhat.com/errata/RHSA-2026:36049 cve-icon
https://access.redhat.com/errata/RHSA-2026:36767 cve-icon
https://access.redhat.com/errata/RHSA-2026:38902 cve-icon
https://access.redhat.com/errata/RHSA-2026:51603 cve-icon
https://access.redhat.com/errata/RHSA-2026:51604 cve-icon
https://access.redhat.com/errata/RHSA-2026:55444 cve-icon
https://access.redhat.com/errata/RHSA-2026:59142 cve-icon
https://access.redhat.com/errata/RHSA-2026:59143 cve-icon
https://access.redhat.com/errata/RHSA-2026:59145 cve-icon
https://access.redhat.com/errata/RHSA-2026:59146 cve-icon
https://access.redhat.com/errata/RHSA-2026:59147 cve-icon
https://access.redhat.com/errata/RHSA-2026:59148 cve-icon
https://access.redhat.com/errata/RHSA-2026:59149 cve-icon
https://access.redhat.com/security/cve/CVE-2026-45984 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2481922 cve-icon
https://git.kernel.org/stable/c/1403989d1b502f4a2c0d0b42ccf1c25748442eff cve-icon cve-icon
https://git.kernel.org/stable/c/1cae1bafdf9caa9b462b19af06b1a06902e4e142 cve-icon cve-icon
https://git.kernel.org/stable/c/6d76febba07c40bcf358f63216d36ea68cf1c215 cve-icon cve-icon
https://git.kernel.org/stable/c/764c3c84b5683e608f43735c803a5f415046686c cve-icon cve-icon
https://git.kernel.org/stable/c/815ddd27c0c7171a99fe802fdb19098ddef8b19d cve-icon cve-icon
https://git.kernel.org/stable/c/87d4954b5c59735a99ea98cb208d47130f6dce7d cve-icon cve-icon
https://git.kernel.org/stable/c/d87268326b277af3665237ac76a73dd9fa8e21b4 cve-icon cve-icon
https://git.kernel.org/stable/c/faddeb848305e79db89ee0479bb0e33380656321 cve-icon cve-icon
https://lore.kernel.org/linux-cve-announce/2026052739-CVE-2026-45984-107d@gregkh/T cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-45984 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45984.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-45984 cve-icon
History

Tue, 25 Aug 2026 13:30:00 +0000


Mon, 17 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
References

Tue, 16 Jun 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 30 May 2026 11:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 28 May 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 28 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-826
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 27 May 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in iomap inline data write path The inline data buffer head (dibh) is being released prematurely in gfs2_iomap_begin() via release_metapath() while iomap->inline_data still points to dibh->b_data. This causes a use-after-free when iomap_write_end_inline() later attempts to write to the inline data area. The bug sequence: 1. gfs2_iomap_begin() calls gfs2_meta_inode_buffer() to read inode metadata into dibh 2. Sets iomap->inline_data = dibh->b_data + sizeof(struct gfs2_dinode) 3. Calls release_metapath() which calls brelse(dibh), dropping refcount to 0 4. kswapd reclaims the page (~39ms later in the syzbot report) 5. iomap_write_end_inline() tries to memcpy() to iomap->inline_data 6. KASAN detects use-after-free write to freed memory Fix by storing dibh in iomap->private and incrementing its refcount with get_bh() in gfs2_iomap_begin(). The buffer is then properly released in gfs2_iomap_end() after the inline write completes, ensuring the page stays alive for the entire iomap operation. Note: A C reproducer is not available for this issue. The fix is based on analysis of the KASAN report and code review showing the buffer head is freed before use. [agruenba: Take buffer head reference in gfs2_iomap_begin() to avoid leaks in gfs2_iomap_get() and gfs2_iomap_alloc().]
Title gfs2: Fix use-after-free in iomap inline data write path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-25T12:05:56.726Z

Reserved: 2026-05-13T15:03:33.090Z

Link: CVE-2026-45984

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-05-27T14:17:15.640

Modified: 2026-08-25T13:19:14.290

Link: CVE-2026-45984

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-45984 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T00:00:05Z

Weaknesses