SB20260905133 - Infinite loop in Linux kernel xfs scrub



SB20260905133 - Infinite loop in Linux kernel xfs scrub

Published: September 5, 2026

Security Bulletin ID SB20260905133
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Infinite loop (CVE-ID: CVE-2026-80820)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of circular linked lists in the XFS scrub unlinked inode list traversal when online filesystem checking processes an unlinked inode list containing a loop. A local user can cause online filesystem checking to traverse the circular list to cause a denial of service.


Remediation

Install update from vendor's website.