« Volver al listado

CVE-2026-80532

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix another iunlink infinite loop bug in online fsck

xrep_iunlink_resolve_bucket is supposed to reconstruct as much of the incore prev and next unlinked list pointers based on what it finds on disk and in memory before we move on to relinking the truly lost inodes back into the unlinked list. However, it's still vulnerable to infinite loops that come in via the next_unlinked pointers.

Fix this problem by remembering which inodes we've already seen and checking new agino pointers against that. If a bit is already set, either this is a loop or the inode has nonzero link count. We'll deal with the second case in a subsequent patch.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80532",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ab97f4b1c030750f2475bf4da8a9554d02206640",
              "lessThan": "24aec8c88539a382355761a9b924046885b6be40",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ab97f4b1c030750f2475bf4da8a9554d02206640",
              "lessThan": "b6baf0db357fb84f3f3cfd33383a00de71a5a1c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ab97f4b1c030750f2475bf4da8a9554d02206640",
              "lessThan": "23690064f235a88a00c04f2e49f36bfb54ae560d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ab97f4b1c030750f2475bf4da8a9554d02206640",
              "lessThan": "6d67c6b99f1fc07c64b97fcbc974c6f1ada7f622",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/xfs/scrub/agheader_repair.c",
            "fs/xfs/scrub/trace.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.105",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.46",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.10",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/xfs/scrub/agheader_repair.c",
            "fs/xfs/scrub/trace.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-26T15:17:07.270",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/23690064f235a88a00c04f2e49f36bfb54ae560d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/24aec8c88539a382355761a9b924046885b6be40",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6d67c6b99f1fc07c64b97fcbc974c6f1ada7f622",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b6baf0db357fb84f3f3cfd33383a00de71a5a1c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix another iunlink infinite loop bug in online fsck\n\nxrep_iunlink_resolve_bucket is supposed to reconstruct as much of the\nincore prev and next unlinked list pointers based on what it finds on\ndisk and in memory before we move on to relinking the truly lost inodes\nback into the unlinked list.  However, it's still vulnerable to infinite\nloops that come in via the next_unlinked pointers.\n\nFix this problem by remembering which inodes we've already seen and\nchecking new agino pointers against that.  If a bit is already set,\neither this is a loop or the inode has nonzero link count.  We'll deal\nwith the second case in a subsequent patch."
    }
  ],
  "lastModified": "2026-08-26T15:17:07.270",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}