CVE-2026-43068

Source
https://cve.org/CVERecord?id=CVE-2026-43068
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43068.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43068
Downstream
Related
Published
2026-05-05T15:23:27.371Z
Modified
2026-07-11T03:54:05.640034880Z
Summary
ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal()
Details

In the Linux kernel, the following vulnerability has been resolved:

ext4: avoid allocate block from corrupted group in ext4mbfindbygoal()

There's issue as follows: ... EXT4-fs (mmcblk0p1): Delayed block allocation failed for inode 206 at logical offset 0 with max blocks 1 with error 117 EXT4-fs (mmcblk0p1): This should not happen!! Data will be lost

EXT4-fs (mmcblk0p1): Delayed block allocation failed for inode 206 at logical offset 0 with max blocks 1 with error 117 EXT4-fs (mmcblk0p1): This should not happen!! Data will be lost

EXT4-fs (mmcblk0p1): Delayed block allocation failed for inode 206 at logical offset 0 with max blocks 1 with error 117 EXT4-fs (mmcblk0p1): This should not happen!! Data will be lost

EXT4-fs (mmcblk0p1): Delayed block allocation failed for inode 206 at logical offset 0 with max blocks 1 with error 117 EXT4-fs (mmcblk0p1): This should not happen!! Data will be lost

EXT4-fs (mmcblk0p1): Delayed block allocation failed for inode 2243 at logical offset 0 with max blocks 1 with error 117 EXT4-fs (mmcblk0p1): This should not happen!! Data will be lost

EXT4-fs (mmcblk0p1): Delayed block allocation failed for inode 2239 at logical offset 0 with max blocks 1 with error 117 EXT4-fs (mmcblk0p1): This should not happen!! Data will be lost

EXT4-fs (mmcblk0p1): error count since last fsck: 1 EXT4-fs (mmcblk0p1): initial error at time 1765597433: ext4mbgeneratebuddy:760 EXT4-fs (mmcblk0p1): last error at time 1765597433: ext4mbgeneratebuddy:760 ...

According to the log analysis, blocks are always requested from the corrupted block group. This may happen as follows: ext4mbfindbygoal ext4mbloadbuddy ext4mbloadbuddygfp ext4mbinitcache ext4readblockbitmapnowait ext4waitblockbitmap ext4validateblockbitmap if (!grp || EXT4MBGRPBBITMAPCORRUPT(grp)) return -EFSCORRUPTED; // There's no logs. if (err) return err; // Will return error ext4lockgroup(ac->acsb, group); if (unlikely(EXT4MBGRPBBITMAPCORRUPT(e4b->bdinfo))) // Unreachable goto out;

After commit 9008a58e5dce ("ext4: make the bitmap read routines return real error codes") merged, Commit 163a203ddb36 ("ext4: mark block group as corrupt on block bitmap error") is no real solution for allocating blocks from corrupted block groups. This is because if 'EXT4MBGRPBBITMAPCORRUPT(e4b->bdinfo)' is true, then 'ext4mbloadbuddy()' may return an error. This means that the block allocation will fail. Therefore, check block group if corrupted when ext4mbload_buddy() returns error.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43068.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
163a203ddb36c36d4a1c942aececda0cc8d06aa7
Fixed
fea6b2e250ff48f10d166011b57a8516ae5438c9
Fixed
0b84571c886719823d537f05f4f07cad6357c4b7
Fixed
ffc0a282462d45fee5957621be5afa29752f3b6d
Fixed
2d31a5073f86a177edf44015e0dedb0c47cfd6d8
Fixed
9370207b36d26e45a8c8ef0500706d37036edd6b
Fixed
1895f7904be71c48f1e6f338b28f24dabd6b8aeb
Fixed
1c0d7c4cde38a887c6d74e0c89ddb25226943c78
Fixed
46066e3a06647c5b186cc6334409722622d05c44

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43068.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.12.0
Fixed
5.10.253
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.203
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.168
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.131
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.80
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.21
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43068.json"