Bug 1262657 (CVE-2026-31463) - VUL-0: CVE-2026-31463: kernel: iomap: fix invalid folio access when i_blkbits differs from I/O granularity
Summary: VUL-0: CVE-2026-31463: kernel: iomap: fix invalid folio access when i_blkbits...
Status: NEW
Alias: CVE-2026-31463
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/511276/
Whiteboard: CVSSv3.1:SUSE:CVE-2026-31463:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2026-04-23 12:02 UTC by SMASH SMASH
Modified: 2026-04-24 04:45 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2026-04-23 12:02:33 UTC
In the Linux kernel, the following vulnerability has been resolved:

iomap: fix invalid folio access when i_blkbits differs from I/O granularity

Commit aa35dd5cbc06 ("iomap: fix invalid folio access after
folio_end_read()") partially addressed invalid folio access for folios
without an ifs attached, but it did not handle the case where
1 << inode->i_blkbits matches the folio size but is different from the
granularity used for the IO, which means IO can be submitted for less
than the full folio for the !ifs case.

In this case, the condition:

  if (*bytes_submitted == folio_len)
    ctx->cur_folio = NULL;

in iomap_read_folio_iter() will not invalidate ctx->cur_folio, and
iomap_read_end() will still be called on the folio even though the IO
helper owns it and will finish the read on it.

Fix this by unconditionally invalidating ctx->cur_folio for the !ifs
case.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-31463
https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-31463.mbox
https://git.kernel.org/stable/c/4a927f670cdb0def226f9f85f42a9f19d9e09c88
https://git.kernel.org/stable/c/bd71fb3fea9945987053968f028a948997cba8cc
https://www.cve.org/CVERecord?id=CVE-2026-31463
https://bugzilla.redhat.com/show_bug.cgi?id=2460670