CVE-2026-31448Patch(linux / linux_kernel)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if inserting a new extent into the extent tree fails (in this example, because the file system disabled the huge file feature when marking the inode as dirty), ext4_ext_map_blocks() only calls ext4_free_blocks() to reclaim the physical block without deleting the corresponding data in the extent tree. This causes subsequent mkdir operations to reference the previously reclaimed physical block number again, even though this physical block is already being used by the xattr block. Therefore, a situation arises where both the directory and xattr are using the same buffer head block in memory simultaneously. The above causes ext4_xattr_block_set() to enter an infinite loop about "inserted" and cannot release the inode lock, ultimately leading to the 143s blocking problem mentioned in [1]. If the metadata is corrupted, then trying to remove some extent space can do even more harm. Also in case EXT4_GET_BLOCKS_DELALLOC_RESERVE was passed, remove space wrongly update quota information. Jan Kara suggests distinguishing between two cases: 1) The error is ENOSPC or EDQUOT - in this case the filesystem is fully consistent and we must maintain its consistency including all the accounting. However these errors can happen only early before we've inserted the extent into the extent tree. So current code works correctly for this case. 2) Some other error - this means metadata is corrupted. We should strive to do as few modifications as possible to limit damage. So I'd just skip freeing of allocated blocks. [1] INFO: task syz.0.17:5995 blocked for more than 143 seconds. Call Trace: inode_lock_nested include/linux/fs.h:1073 [inline] __start_dirop fs/namei.c:2923 [inline] start_dirop fs/namei.c:2934 [inline]

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked 1d ago at 2 mentions (2026-04-22); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-22: 2Mentions · 2026-04-23: 1Patch / Workaround · 2026-04-22: 2Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 104-2204-23
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-222
Patch2
2026-04-231
Patch1
Full discourse3 posts
  • WindowsForum@windowsforum
    Patch

    🪟 Linux ext4 “infinite loop” CVE-2026-31448 is the kind of bug that turns a filesystem into a never-ending rerun. Fun for servers, terrible for admins—patch yesterday. #WindowsForum https://windowsforum.com/threads/cve-2026-31448-ext4-infinite-loop-extent-xattr-bug-and-patch-guidance.414726/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #Ext4Vulnerability #Cve202631448 #SystemAvailability https://t.co/qpr5OJYhlY

    Post summary

    The tweet announces that CVE‑2026‑31448, an ext4 infinite‑loop bug, has been patched and supplies a link to patch guidance, but it does not disclose any PoC or active exploitation.

    0000038
    1.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-31448 In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical… https://www.cve.org/CVERecord?id=CVE-2026-31448 ----- Traducción: CVE-2026-31448 En … http://infoflow.cloud`

    Post summary

    CVE-2026-31448, a Linux kernel ext4 issue causing infinite loops on mkdir/mknod paths, has been resolved with a patch.

    0000039
    72 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31448 In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical… https://www.cve.org/CVERecord?id=CVE-2026-31448

    Post summary

    The entry declares that CVE-2026-31448, an infinite-loop flaw in ext4, has been fixed in the Linux kernel, indicating a corrective patch has been applied.

    00000167
    57.2K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel2.6.22--
OSlinuxlinux_kernel2.6.22--
OSlinuxlinux_kernel2.6.22--
OSlinuxlinux_kernel2.6.22--
OSlinuxlinux_kernel2.6.22--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more