Linux Kernel iomap Component Invalid Folio Access Vulnerability

Vulnerability

A vulnerability in the Linux kernel's iomap component can lead to invalid access of folio structures when the block size differs from the I/O granularity. This issue arises in folios without an associated I/O folio state (ifs), where the block size matches the folio size but the I/O granularity is smaller. In such cases, I/O can be submitted for less than the full folio, causing the I/O helper to incorrectly manage folio ownership. The vulnerability affects the Linux kernel stable tree.

Impact

Exploitation of this vulnerability can disrupt the proper management of folio ownership during I/O operations, potentially leading to incorrect I/O handling or data corruption.

Remediation

Users can upgrade to the latest version of the Linux kernel stable tree, where this vulnerability has been addressed.

Added: Apr 22, 2026, 3:33 PM
Updated: Apr 22, 2026, 3:33 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
3.5
remediation
7.7
relevance
6.2
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.