CVE-2026-31446Patch(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in update_super_work when racing with umount Commit b98535d09179 ("ext4: fix bug_on in start_this_handle during umount filesystem") moved ext4_unregister_sysfs() before flushing s_sb_upd_work to prevent new error work from being queued via /proc/fs/ext4/xx/mb_groups reads during unmount. However, this introduced a use-after-free because update_super_work calls ext4_notify_error_sysfs() -> sysfs_notify() which accesses the kobject's kernfs_node after it has been freed by kobject_del() in ext4_unregister_sysfs(): update_super_work ext4_put_super ----------------- -------------- ext4_unregister_sysfs(sb) kobject_del(&sbi->s_kobj) __kobject_del() sysfs_remove_dir() kobj->sd = NULL sysfs_put(sd) kernfs_put() // RCU free ext4_notify_error_sysfs(sbi) sysfs_notify(&sbi->s_kobj) kn = kobj->sd // stale pointer kernfs_get(kn) // UAF on freed kernfs_node ext4_journal_destroy() flush_work(&sbi->s_sb_upd_work) Instead of reordering the teardown sequence, fix this by making ext4_notify_error_sysfs() detect that sysfs has already been torn down by checking s_kobj.state_in_sysfs, and skipping the sysfs_notify() call in that case. A dedicated mutex (s_error_notify_mutex) serializes ext4_notify_error_sysfs() against kobject_del() in ext4_unregister_sysfs() to prevent TOCTOU races where the kobject could be deleted between the state_in_sysfs check and the sysfs_notify() call.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-22); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-22: 2Mentions · 2026-04-23: 1Patch / Workaround · 2026-04-22: 2Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 104-2204-23
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-222
Patch2
2026-04-231
Disclosure1
Full discourse3 posts
  • WindowsForum@windowsforum
    Disclosure

    🪟 UAF race in ext4 sysfs teardown… aka “it only breaks when you’re stressed and the disk is screaming.” Fixing timing bugs matters more than flashy exploits. #WindowsForum #Linux #CVE https://windowsforum.com/threads/cve-2026-31446-ext4-uaf-fixing-a-sysfs-teardown-race.414790/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #KernelConcurrency #LinuxKernelSecurity #Ext4UseAfterFree https://t.co/Pq86dpaGJF

    Post summary

    The tweet references a use-after-free race in ext4 sysfs teardown (CVE-2026-31446) but provides only general comments without a PoC, exploit, patch, or evidence of active exploitation.

    0100047
    1.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-31446 In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in update_super_work when racing with umount Commit b98535d09179 ("ext4… https://www.cve.org/CVERecord?id=CVE-2026-31446 ----- Traducción: CVE-2026-31446 En … http://infoflow.cloud`

    Post summary

    The message announces that CVE-2026-31446 in the Linux kernel has been fixed via a commit, indicating a patch availability rather than an exploit or active threat.

    0000038
    72 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31446 In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in update_super_work when racing with umount Commit b98535d09179 ("ext4… https://www.cve.org/CVERecord?id=CVE-2026-31446

    Post summary

    The Linux kernel ext4 filesystem use‑after‑free bug (CVE-2026-31446) was fixed in commit b98535d09179, effectively patching the vulnerability.

    00000174
    57.2K followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.18--
OSlinuxlinux_kernel5.18--
OSlinuxlinux_kernel5.18--
OSlinuxlinux_kernel5.18--
OSlinuxlinux_kernel5.18--
OSlinuxlinux_kernel5.18--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more