Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43187
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause data loss.
The vulnerability exists due to improper state management in the XFS extended attribute leaf freemap handling code when processing setxattr operations. A local user can set extended attributes in a way that causes xattr namevalue entries to be allocated on top of the entries array to cause data loss.
The issue involves zero-length freemap entries with a nonzero base and can lead to overlapping freemap entries with the same base but different sizes.
How to mitigate CVE-2026-43187
Sources
- https://git.kernel.org/stable/c/479b05fc3ee272090f671b06a41f3da8aa78eece
- https://git.kernel.org/stable/c/6f13c1d2a6271c2e73226864a0e83de2770b6f34
- https://git.kernel.org/stable/c/a631899025d47ea1aa6464d76db5b4d3b6d196fd
- https://git.kernel.org/stable/c/aa9083d97e2157da3c6fb45ddb1a97af7f188f7f
- https://git.kernel.org/stable/c/e1b8c6452ee99a30e188a88f3f3f804fb1c6004a
- https://git.kernel.org/stable/c/f31a8334e1c54b126fcecf98645a49b6bc5ad399
- https://git.kernel.org/stable/c/f3c0d1fc1eadbb4adbee5ab7757d41d35f48325b
- https://git.kernel.org/stable/c/ffaf5c99d0f862db021fb1af8b813c1416b1beb2