8.4

CVE-2026-80536

xfs: bounds-check buffer log item's dirty bitmap

In the Linux kernel, the following vulnerability has been resolved:

xfs: bounds-check buffer log item's dirty bitmap

xlog_recover_do_reg_buffer() replays each dirty region described by a
buffer log item's bitmap into the buffer read for that item:

	memcpy(xfs_buf_offset(bp, (uint)bit << XFS_BLF_SHIFT),
		item->ri_buf[i].iov_base,
		nbits << XFS_BLF_SHIFT);

The destination offset (bit/nbits, from the logged dirty bitmap) and the
buffer size (from the logged blf_len) are both attacker-controlled and
otherwise unrelated, yet the only thing bounding the copy is an ASSERT(),
which compiles away on production kernels. A crafted image logging a
small blf_len together with a bitmap bit past the end of that buffer
drives the memcpy() past the buffer's allocation, corrupting adjacent
kernel heap during mount-time log recovery. This is reachable by anyone
who can get a crafted image mounted -- the malicious-filesystem threat
model XFS already guards against elsewhere.

Turn the ASSERT() into a real XFS_IS_CORRUPT() check that aborts recovery
of the buffer with -EFSCORRUPTED, consistent with the validate-and-fail
idiom already used in xlog_recover_do_inode_buffer() and
xfs_dquot_item_recover.c. xlog_recover_do_reg_buffer() therefore becomes
STATIC int and its three callers propagate the error.

Found and confirmed with KASAN on a CONFIG_XFS_DEBUG=n build: the crafted
image trips a slab-out-of-bounds write before this change and fails
recovery cleanly with -EFSCORRUPTED after it.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < acb4e26295e7f0e685815a3fd3d70bd8329cefa1
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < f3859c35a4fbc1c1c58431f684f808e43696891d
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < f7b5fa83e2c192be922121b764415fa8c7549ea1
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < b7528b42813f02724a78fce1da24d69d1bfc4d38
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 7e32d4eebae6ca24f8a673c107fd7eca1f47afc2
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < f8288214459ead7e87d26e5822f62c14a4f2ed6b
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < edaf5b6bd625356893da20d69a259b34a9de2694
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 813f8136a2ce1fee266d02a7df73db6e8a541604
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.267
Status unaffected
Version <= 5.15.*
Version 5.15.218
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.039
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f8288214459ead7e87d26e5822f62c14a4f2ed6b
https://git.kernel.org/stable/c/edaf5b6bd625356893da20d69a259b34a9de2694
https://git.kernel.org/stable/c/813f8136a2ce1fee266d02a7df73db6e8a541604
https://git.kernel.org/stable/c/7e32d4eebae6ca24f8a673c107fd7eca1f47afc2
https://git.kernel.org/stable/c/acb4e26295e7f0e685815a3fd3d70bd8329cefa1
https://git.kernel.org/stable/c/b7528b42813f02724a78fce1da24d69d1bfc4d38
https://git.kernel.org/stable/c/f3859c35a4fbc1c1c58431f684f808e43696891d
https://git.kernel.org/stable/c/f7b5fa83e2c192be922121b764415fa8c7549ea1