-

CVE-2026-97551

xfs: initialise args->total for parent pointer updates

In the Linux kernel, the following vulnerability has been resolved:

xfs: initialise args->total for parent pointer updates

xfs_parent_da_args_init() builds an xfs_da_args from a zeroed
xfs_parent_args (kmem_cache_zalloc), leaving args->total == 0.
xfs_da_grow_inode_int() treats that field as a running block reservation
and subtracts from it; because it is an xfs_extlen_t (uint32_t), the
first attr-fork growth wraps it to ~0U.  That defeats the free-space
check in xfs_alloc_space_available(), and when it coincides with an AG
that has exactly zero available blocks the allocation is clamped to
maxlen 0 and returns -ENOSPC, which xfs_defer_finish_noroll() escalates
to a filesystem shutdown.

Set args->total the way the log recovery path does
(xfs_attri_recover_work(), xfs_attr_item.c:706), in the add and replace
paths that can grow the fork.  Removals and lookups never grow it, so
they leave the field alone, matching that switch.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b7c62d90c12c6cc86f10b8a62cefe0029374b6ff
Version < 9ad85bce62cadfdf4242f6e6bbff2a52e51d30f1
Status affected
Version b7c62d90c12c6cc86f10b8a62cefe0029374b6ff
Version < c66e138af626cad4210da449996ae9e07ee63add
Status affected
Version b7c62d90c12c6cc86f10b8a62cefe0029374b6ff
Version < ac9032882d673dd6679e1d873a2dc0131a1aeb43
Status affected
Version b7c62d90c12c6cc86f10b8a62cefe0029374b6ff
Version < 8e4ebb6afaa34bd2e8ce52da231003d24111c2d6
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.10
Status affected
Version 0
Version < 6.10
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9ad85bce62cadfdf4242f6e6bbff2a52e51d30f1
https://git.kernel.org/stable/c/c66e138af626cad4210da449996ae9e07ee63add
https://git.kernel.org/stable/c/ac9032882d673dd6679e1d873a2dc0131a1aeb43
https://git.kernel.org/stable/c/8e4ebb6afaa34bd2e8ce52da231003d24111c2d6