{"id":"CVE-2026-98161","summary":"nvdimm: pmem: keep PREFLUSH before data writes","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm: pmem: keep PREFLUSH before data writes\n\npmem_submit_bio() records a REQ_PREFLUSH error, but continues to copy the\nbio data and can later overwrite the error with a successful REQ_FUA flush.\nThat lets data writes run after a failed preflush and can complete the bio\nsuccessfully despite the failed ordering barrier.\n\nRun the REQ_PREFLUSH flush synchronously before touching the bio data and\ncomplete the bio with the flush error if it fails. Keep asynchronous flush\nchaining for REQ_FUA. At that point, data copy has completed and the parent\nbio can wait for the chained flush bio.","modified":"2026-10-01T11:30:43.891031328Z","published":"2026-09-25T13:06:51.138Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98161.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/72561ca1ab96f0f0f32737a6171641e05a318538"},{"type":"WEB","url":"https://git.kernel.org/stable/c/770a90c2127220f0fc194ce909ad4f0842e141cb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c644a2f8fef5618fcf453c591177700fd07dd024"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98161.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98161"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"c5d4355d10d414a96ca870b731756b89d068d57a"},{"fixed":"770a90c2127220f0fc194ce909ad4f0842e141cb"},{"fixed":"72561ca1ab96f0f0f32737a6171641e05a318538"},{"fixed":"c644a2f8fef5618fcf453c591177700fd07dd024"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-98161.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.3.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-98161.json"}}],"schema_version":"1.9.0"}