CVE-2026-23252
In the Linux kernel, the following vulnerability has been resolved:
xfs: get rid of the xchk_xfile_*_descr calls
The xchk_xfile_*_descr macros call kasprintf, which can fail to allocate memory if the formatted string is larger than 16 bytes (or whatever the nofail guarantees are nowadays). Some of them could easily exceed that, and Jiaming Zhang found a few places where that can happen with syzbot.
The descriptions are debugging aids and aren't required to be unique, so let's just pass in static strings and eliminate this path to failure. Note this patch touches a number of commits, most of which were merged between 6.6 and 6.14.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23252",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ab97f4b1c030750f2475bf4da8a9554d02206640",
"lessThan": "695455fbc49053cbf555f2f302a5dcd600f412ff",
"versionType": "git"
},
{
"status": "affected",
"version": "ab97f4b1c030750f2475bf4da8a9554d02206640",
"lessThan": "18e9cf2259b4157fd282b323514375f2f6a59edb",
"versionType": "git"
},
{
"status": "affected",
"version": "ab97f4b1c030750f2475bf4da8a9554d02206640",
"lessThan": "2d8afee89262762fe0e5547772708c75f320c957",
"versionType": "git"
},
{
"status": "affected",
"version": "ab97f4b1c030750f2475bf4da8a9554d02206640",
"lessThan": "60382993a2e18041f88c7969f567f168cd3b4de3",
"versionType": "git"
}
],
"programFiles": [
"fs/xfs/scrub/agheader_repair.c",
"fs/xfs/scrub/alloc_repair.c",
"fs/xfs/scrub/attr_repair.c",
"fs/xfs/scrub/bmap_repair.c",
"fs/xfs/scrub/common.h",
"fs/xfs/scrub/dir.c",
"fs/xfs/scrub/dir_repair.c",
"fs/xfs/scrub/dirtree.c",
"fs/xfs/scrub/ialloc_repair.c",
"fs/xfs/scrub/nlinks.c",
"fs/xfs/scrub/parent.c",
"fs/xfs/scrub/parent_repair.c",
"fs/xfs/scrub/quotacheck.c",
"fs/xfs/scrub/refcount_repair.c",
"fs/xfs/scrub/rmap_repair.c",
"fs/xfs/scrub/rtbitmap_repair.c",
"fs/xfs/scrub/rtrefcount_repair.c",
"fs/xfs/scrub/rtrmap_repair.c",
"fs/xfs/scrub/rtsummary.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/xfs/scrub/agheader_repair.c",
"fs/xfs/scrub/alloc_repair.c",
"fs/xfs/scrub/attr_repair.c",
"fs/xfs/scrub/bmap_repair.c",
"fs/xfs/scrub/common.h",
"fs/xfs/scrub/dir.c",
"fs/xfs/scrub/dir_repair.c",
"fs/xfs/scrub/dirtree.c",
"fs/xfs/scrub/ialloc_repair.c",
"fs/xfs/scrub/nlinks.c",
"fs/xfs/scrub/parent.c",
"fs/xfs/scrub/parent_repair.c",
"fs/xfs/scrub/quotacheck.c",
"fs/xfs/scrub/refcount_repair.c",
"fs/xfs/scrub/rmap_repair.c",
"fs/xfs/scrub/rtbitmap_repair.c",
"fs/xfs/scrub/rtrefcount_repair.c",
"fs/xfs/scrub/rtrmap_repair.c",
"fs/xfs/scrub/rtsummary.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-03-18T18:16:23.233",
"references": [
{
"url": "https://git.kernel.org/stable/c/18e9cf2259b4157fd282b323514375f2f6a59edb",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2d8afee89262762fe0e5547772708c75f320c957",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/60382993a2e18041f88c7969f567f168cd3b4de3",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/695455fbc49053cbf555f2f302a5dcd600f412ff",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: get rid of the xchk_xfile_*_descr calls\n\nThe xchk_xfile_*_descr macros call kasprintf, which can fail to allocate\nmemory if the formatted string is larger than 16 bytes (or whatever the\nnofail guarantees are nowadays). Some of them could easily exceed that,\nand Jiaming Zhang found a few places where that can happen with syzbot.\n\nThe descriptions are debugging aids and aren't required to be unique, so\nlet's just pass in static strings and eliminate this path to failure.\nNote this patch touches a number of commits, most of which were merged\nbetween 6.6 and 6.14."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nxfs: eliminar las llamadas a xchk_xfile_*_descr\n\nLas macros xchk_xfile_*_descr llaman a kasprintf, lo que puede fallar al asignar memoria si la cadena formateada es mayor de 16 bytes (o cualesquiera que sean las garantías de nofail hoy en día). Algunas de ellas podrían exceder fácilmente eso, y Jiaming Zhang encontró algunos lugares donde eso puede ocurrir con syzbot.\n\nLas descripciones son ayudas de depuración y no se requiere que sean únicas, así que simplemente pasemos cadenas estáticas y eliminemos esta ruta de fallo. Nótese que este parche afecta a varios commits, la mayoría de los cuales fueron fusionados entre 6.6 y 6.14."
}
],
"lastModified": "2026-06-17T10:21:11.427",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA007D53-8D99-404A-8E76-341B5D45F5B3",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "6.10"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4B8CDA9-BADF-4CF5-8B3B-702DE8EEA40B",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "373EEEDA-FAA1-4FB4-B6ED-DB4DD99DBE67",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "6.19"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}