CVE-2026-97551 PUBLISHED

xfs: initialise args->total for parent pointer updates

Assigner: Linux
Reserved: 24.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

xfs: initialise args->total for parent pointer updates

xfs_parent_da_args_init() builds an xfs_da_args from a zeroed xfs_parent_args (kmem_cache_zalloc), leaving args->total == 0. xfs_da_grow_inode_int() treats that field as a running block reservation and subtracts from it; because it is an xfs_extlen_t (uint32_t), the first attr-fork growth wraps it to ~0U. That defeats the free-space check in xfs_alloc_space_available(), and when it coincides with an AG that has exactly zero available blocks the allocation is clamped to maxlen 0 and returns -ENOSPC, which xfs_defer_finish_noroll() escalates to a filesystem shutdown.

Set args->total the way the log recovery path does (xfs_attri_recover_work(), xfs_attr_item.c:706), in the add and replace paths that can grow the fork. Removals and lookups never grow it, so they leave the field alone, matching that switch.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from b7c62d90c12c6cc86f10b8a62cefe0029374b6ff to 9ad85bce62cadfdf4242f6e6bbff2a52e51d30f1 (excl.)
  • affected from b7c62d90c12c6cc86f10b8a62cefe0029374b6ff to c66e138af626cad4210da449996ae9e07ee63add (excl.)
  • affected from b7c62d90c12c6cc86f10b8a62cefe0029374b6ff to ac9032882d673dd6679e1d873a2dc0131a1aeb43 (excl.)
  • affected from b7c62d90c12c6cc86f10b8a62cefe0029374b6ff to 8e4ebb6afaa34bd2e8ce52da231003d24111c2d6 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.10 is affected
  • unaffected from 0 to 6.10 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References