CVE-2026-74362

medium

Description

In the Linux kernel, the following vulnerability has been resolved: ext2: fix ignored return value of generic_write_sync() Fix ext2_dio_write_iter() to propagate the error returned by generic_write_sync() instead of silently discarding it, which could cause write(2) to return success to userspace on O_SYNC/O_DSYNC files even when the sync failed. The correct pattern, already used in ext2_dax_write_iter() in the same file and in ext4, xfs, f2fs among others, is: if (ret > 0) ret = generic_write_sync(iocb, ret); Found by Linux Verification Center (linuxtesting.org) with SVACE. [JK: Reflect also filemap_write_and_wait() return value]

References

https://git.kernel.org/stable/c/ffa974b2f50ad8b911b9066d7aed84ad0afabcdb

https://git.kernel.org/stable/c/b6bc07e49a5fbb335f56eb90cd63dec6584c77d3

https://git.kernel.org/stable/c/a4659be0bc7cb1856ffb15b67f903229ae8891ec

https://git.kernel.org/stable/c/8d70b3973020e59845c0bdad90e0b9c2295fd493

https://git.kernel.org/stable/c/8990dbb7065b0b002b1e58b9091a5b61f5e94dbe

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00168