SB20260827103 - Improper locking in Linux kernel xfs
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper locking (CVE-ID: CVE-2026-80534)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock release in xfs_dq_get_next_id when handling an error from xfs_iread_extents. A local user can trigger the error condition during quota operations to cause a denial of service.
The issue can leave the quota inode locked, causing subsequent quota operations to hang.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0865e4fca02e418fd2423fae9a887dee87b778a1
- https://git.kernel.org/stable/c/08bed2b67d2ee79d3e138c344d8dcfa4c9b26a38
- https://git.kernel.org/stable/c/514a5d42d4188fc5f1499a8d654c717ebf981193
- https://git.kernel.org/stable/c/63320a0f70f66f311f4bccff3af0719c2119f46c
- https://git.kernel.org/stable/c/6401b99a285cd4cfb2949ba44675541b91ad7e4f
- https://git.kernel.org/stable/c/e270d539b8a2e0cb8f617fee47a7b083c0088361
- https://git.kernel.org/stable/c/ed8bfb43de71213cfdbbe833b2c2817250e18b1a