CVE-2026-74362
ext2: fix ignored return value of generic_write_sync()
Description
In the Linux kernel, the following vulnerability has been resolved: ext2: fix ignored return value of generic_write_sync() Fix ext2_dio_write_iter() to propagate the error returned by generic_write_sync() instead of silently discarding it, which could cause write(2) to return success to userspace on O_SYNC/O_DSYNC files even when the sync failed. The correct pattern, already used in ext2_dax_write_iter() in the same file and in ext4, xfs, f2fs among others, is: if (ret > 0) ret = generic_write_sync(iocb, ret); Found by Linux Verification Center (linuxtesting.org) with SVACE. [JK: Reflect also filemap_write_and_wait() return value]
INFO
Published Date :
Aug. 15, 2026, 6:22 a.m.
Last Modified :
Aug. 15, 2026, 6:22 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products
The following products are affected by CVE-2026-74362
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
No affected product recoded yet
Solution
- Update the Linux kernel to the latest stable version.
- Ensure error codes from generic_write_sync are propagated.
- Test write operations with O_SYNC and O_DSYNC flags.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-74362.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-74362 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-74362
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-74362 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-74362 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'fb5de4358e1aa4753dce73c4dc1aca73ff39cedd', 'lessThan': '8990dbb7065b0b002b1e58b9091a5b61f5e94dbe', 'versionType': 'git'}, {'status': 'affected', 'version': 'fb5de4358e1aa4753dce73c4dc1aca73ff39cedd', 'lessThan': '8d70b3973020e59845c0bdad90e0b9c2295fd493', 'versionType': 'git'}, {'status': 'affected', 'version': 'fb5de4358e1aa4753dce73c4dc1aca73ff39cedd', 'lessThan': 'ffa974b2f50ad8b911b9066d7aed84ad0afabcdb', 'versionType': 'git'}, {'status': 'affected', 'version': 'fb5de4358e1aa4753dce73c4dc1aca73ff39cedd', 'lessThan': 'b6bc07e49a5fbb335f56eb90cd63dec6584c77d3', 'versionType': 'git'}, {'status': 'affected', 'version': 'fb5de4358e1aa4753dce73c4dc1aca73ff39cedd', 'lessThan': 'a4659be0bc7cb1856ffb15b67f903229ae8891ec', 'versionType': 'git'}], 'programFiles': ['fs/ext2/file.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.5'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.5', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/ext2/file.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: ext2: fix ignored return value of generic_write_sync() Fix ext2_dio_write_iter() to propagate the error returned by generic_write_sync() instead of silently discarding it, which could cause write(2) to return success to userspace on O_SYNC/O_DSYNC files even when the sync failed. The correct pattern, already used in ext2_dax_write_iter() in the same file and in ext4, xfs, f2fs among others, is: if (ret > 0) ret = generic_write_sync(iocb, ret); Found by Linux Verification Center (linuxtesting.org) with SVACE. [JK: Reflect also filemap_write_and_wait() return value] Added Reference https://git.kernel.org/stable/c/8990dbb7065b0b002b1e58b9091a5b61f5e94dbe Added Reference https://git.kernel.org/stable/c/8d70b3973020e59845c0bdad90e0b9c2295fd493 Added Reference https://git.kernel.org/stable/c/a4659be0bc7cb1856ffb15b67f903229ae8891ec Added Reference https://git.kernel.org/stable/c/b6bc07e49a5fbb335f56eb90cd63dec6584c77d3 Added Reference https://git.kernel.org/stable/c/ffa974b2f50ad8b911b9066d7aed84ad0afabcdb