Integer overflow in Linux kernel - CVE-2026-64256
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer overflow in dqiterate in fs/xfs/scrub/dqiterate.c when iterating quota records. A local user can trigger processing of a filesystem containing a quota record with the maximum quota id to cause a denial of service.
The issue can cause the iteration to wrap to zero and start over.