SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89601

HIGH · CVSS 8.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the ext2 filesystem in the Linux kernel, specifically concerning IS_SYNC inodes where updates may be lost due to improper handling in the `ext2_setsize()` and `ext2_xattr_set2()` functions. This flaw can lead to data integrity issues, as inode updates may not be properly synchronized, potentially resulting in data loss. System administrators and developers managing Linux environments with ext2 filesystems should prioritize applying the fix to mitigate the risk of lost inode updates.

CVE
CVE-2026-89601
Severity
HIGH
CVSS
8.8
EPSS
0.35%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ext2: Fix lost inode updates for IS_SYNC inodes ext2_setsize() and ext2_xattr_set2() had a construct like: if (IS_SYNC(inode)) { sync_inode_metadata(inode, 1); } else { mark_inode_dirty(inode); } which leads to lost inode updates for IS_SYNC inodes because sync_inode_metadata() does anything only if the inode is already dirty and hence inode updates may be simply lost. Fix the problem by unconditionally marking the inode dirty and *then* call sync_inode_metadata().