Insufficient Control Flow Management in Linux kernel - CVE-2026-97520
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify data and cause a denial of service.
The vulnerability exists due to improper control flow management in gfs2_quota_init() when processing quota change entries. A remote attacker can exploit incorrect quota-change iterator progression to modify data and cause a denial of service.
User interaction is required.