SB20260827108 - Improper Check or Handling of Exceptional Conditions in Linux kernel xfs
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-80529)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause filesystem corruption.
The vulnerability exists due to improper handling of error conditions in xlog_recover_dquot_commit_pass2() when recovering quota log items. A local user can trigger quota recovery involving a corrupted dquot to cause filesystem corruption.
The issue occurs because a recovered dquot verification failure is discarded, allowing log recovery to proceed as if the dquot were valid and enabling a corrupt quota buffer to be written back to disk.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/36a31b12540c0a0a3b77a01fda86de646f2961fb
- https://git.kernel.org/stable/c/38a4dbe588bd028a07a77dc5cee62ee3ce21e87d
- https://git.kernel.org/stable/c/5b756fbb60b5d26063f46a11a3c7daa7eb616d79
- https://git.kernel.org/stable/c/a233b3362a3c7bf23f5143b4ef4b17ec337fcb4d
- https://git.kernel.org/stable/c/e2b4a856085e9bd939bde2dee0d08b1d41babde9
- https://git.kernel.org/stable/c/e506e127fcb4e2bad1045805f1740b395eea9618