
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-100073 is a Linux kernel vulnerability in the ext4 filesystem's transaction credit reservation mechanism during writeback operations. The flaw was introduced by commit 95ad8ee45cdb ("ext4: correct the reserved credits for extent conversion"), which insufficiently estimated the number of journal transaction credits needed when converting extents during sparse folio dirtying. Affected Linux kernel versions include 6.16.3 through 6.17 (semver) and specific git commit ranges starting from 95ad8ee45cdb. It was published on September 25, 2026, with a CVSS category estimate of Medium (GitHub Advisory, Feedly).
The root cause is an underestimation of journal transaction credits in the ext4 extent conversion path during writeback. When a large unwritten extent is sparsely dirtied, the kernel may need to split it into multiple smaller written extents, requiring not only leaf extent block modifications but also the allocation of new extent tree nodes. The prior fix (commit 95ad8ee45cdb) accounted for leaf-level operations but failed to reserve credits for internal tree node allocations, leading to transaction overflow in corner cases. The fix replaces the insufficient credit estimate with a call to ext4_meta_trans_blocks(), which provides a correct upper bound (GitHub Advisory, Kernel Patch 1, Kernel Patch 2).
Successful exploitation can cause ext4 filesystem writeback to fail due to transaction overflow, potentially resulting in a kernel crash or filesystem corruption. The impact is limited to availability (Denial of Service), as a local user with write access to files on an ext4 filesystem can trigger the condition by performing sparse writes to large folios. There is no evidence of confidentiality or integrity impact beyond potential filesystem data loss from the crash or corruption (Feedly, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability requires local access with write permissions to files on an ext4 filesystem, limiting the attack surface. The EPSS score is 0.00145 (approximately 0.15%), reflecting a low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly, GitHub Advisory).
Apply the Linux kernel patches that correct the transaction credit estimation by replacing the insufficient estimate with a call to ext4_meta_trans_blocks(). Two stable-branch patches are available: commit a22464c5df5827e884a5a7d3d8fb03870e5bb6c8 and commit 46e8e31771f4f1c5e1cdec37a889a6730e42e9f1. Kernel versions 6.16.3 through 6.17 should be updated to a patched release; as a temporary workaround, restricting local write access to ext4 filesystems or disabling writeback on affected systems can reduce risk until patching is feasible (Kernel Patch 1, Kernel Patch 2, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."