CVE-2026-93140 PUBLISHED

udf: Mark LVID buffer as uptodate before marking it dirty

Assigner: Linux
Reserved: 17.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

udf: Mark LVID buffer as uptodate before marking it dirty

When an I/O error occurs while writing the Logical Volume Integrity Descriptor (LVID) buffer to the block device, the block layer's completion handler (end_buffer_write_sync()) clears the BH_Uptodate flag on the buffer. However, the buffer still contains valid LVID data in memory. If the filesystem is subsequently remounted read-write or synced, udf_open_lvid() or udf_sync_fs() will modify the LVID buffer and call mark_buffer_dirty(). This triggers a spurious WARN_ON_ONCE(!buffer_uptodate(bh)) warning in mark_buffer_dirty() because the buffer is not marked uptodate, even though its in-memory contents are valid and are about to be overwritten.

To prevent this spurious warning, unconditionally set the BH_Uptodate flag before calling mark_buffer_dirty() in udf_open_lvid() and udf_sync_fs(). This acknowledges that the in-memory buffer is valid and matches the workaround previously applied to udf_close_lvid() in commit 853a0c25baf9 ("udf: Mark LVID buffer as uptodate before marking it dirty"). Extending this workaround ensures consistent behavior across all LVID updates.

Buffer I/O error on dev loop0, logical block 128, lost sync page write ------------[ cut here ]------------ !buffer_uptodate(bh) WARNING: fs/buffer.c:1087 at mark_buffer_dirty+0x299/0x410 fs/buffer.c:1087 ... Call Trace: <TASK> udf_open_lvid+0x369/0x5b0 fs/udf/super.c:2078 udf_reconfigure+0x336/0x540 fs/udf/super.c:679 reconfigure_super+0x232/0x8f0 fs/super.c:1080 vfs_cmd_reconfigure fs/fsopen.c:268 [inline] vfs_fsconfig_locked+0x171/0x320 fs/fsopen.c:297 __do_sys_fsconfig fs/fsopen.c:463 [inline] __se_sys_fsconfig+0x6b9/0x810 fs/fsopen.c:350 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94 </TASK>

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 853a0c25baf96b028de1654bea1e0c8857eadf3d to e6461ef34f91ad7dbffdf912b3d661a7dd892931 (excl.)
  • affected from 853a0c25baf96b028de1654bea1e0c8857eadf3d to 359cea636f4a74a96c01a8050f155e12840c079a (excl.)
  • affected from 853a0c25baf96b028de1654bea1e0c8857eadf3d to a4c4e38b356ad4c1f90478124922917489137c08 (excl.)
  • affected from 853a0c25baf96b028de1654bea1e0c8857eadf3d to 8034ddf4751d9143c5ef7eebe3d4f33218fdd378 (excl.)
  • affected from 853a0c25baf96b028de1654bea1e0c8857eadf3d to ee477e5204f764444e60699280abf5936c2a6ae6 (excl.)
  • affected from 853a0c25baf96b028de1654bea1e0c8857eadf3d to 11afe1912140f79d5af3091a54b181ef72fce1a5 (excl.)
  • affected from 853a0c25baf96b028de1654bea1e0c8857eadf3d to c4058355d27488a3cd31c60c032335f77c4fdcfc (excl.)
  • affected from 853a0c25baf96b028de1654bea1e0c8857eadf3d to fb0601134c7e51728bd098abc6909315de1e5d86 (excl.)
  • Version c7da4ed95a78e38fdaffb06eaf1a3f3318b1add6 is affected
  • Version c005218328597211008a4d33a91e2952798e3556 is affected
  • Version 1357ed0b4b9db30846377febb40a847d6103c991 is affected
  • Version 43f4a516b2f5492bc597f3753b693ad8adc62748 is affected
  • affected from 2.6.27.62 to 2.6.28 (excl.)
  • affected from 2.6.32.57 to 2.6.33 (excl.)
  • affected from 3.0.21 to 3.1 (excl.)
  • affected from 3.2.6 to 3.3 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.3 is affected
  • unaffected from 0 to 3.3 (excl.)
  • unaffected from 5.10.270 to 5.10.* (incl.)
  • unaffected from 5.15.221 to 5.15.* (incl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References