PT-2026-43851 · Linux+2 · Linux Kernel+2

·

CVE-2026-45984

·

Published

2026-05-27

·

Updated

2026-07-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the gfs2 iomap inline data write path. The inline data buffer head dibh is released prematurely in the gfs2 iomap begin() function via release metapath(), while iomap->inline data still points to dibh->b data. This leads to a use-after-free condition when iomap write end inline() subsequently attempts to write to the inline data area. The process involves gfs2 iomap begin() calling gfs2 meta inode buffer() to read inode metadata into dibh, setting iomap->inline data, and then calling release metapath(), which triggers brelse(dibh) and drops the reference count to zero, allowing the page to be reclaimed before the write operation occurs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:27789
ALSA-2026:33743
ALSA-2026:36049
CVE-2026-45984
OESA-2026-2580
OESA-2026-2676
OPENSUSE-SU-2026:20965-1
RHSA-2026:27789
RHSA-2026:33743
SUSE-SU-2026:22099-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:22112-1
SUSE-SU-2026:22117-1
SUSE-SU-2026:22127-1
SUSE-SU-2026:22137-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:2482-1
SUSE-SU-2026:2591-1
SUSE-SU-2026:2630-1
SUSE-SU-2026:2631-1
SUSE-SU-2026:2632-1
SUSE-SU-2026:2638-1
SUSE-SU-2026:2658-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8597-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8610-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux