CVE-2026-80534
In the Linux kernel, the following vulnerability has been resolved:
xfs: fix ilock leak on error in xfs_dq_get_next_id
xfs_dq_get_next_id() takes the quota inode ILOCK before calling xfs_iread_extents(). If xfs_iread_extents() fails, the function returns immediately without releasing the lock, leaking the quota inode ILOCK. This can leave the quota inode locked and cause subsequent quota operations to hang.
Fix this by jumping to a common unlock path on error instead of returning directly.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0865e4fca02e418fd2423fae9a887dee87b778a1
- https://git.kernel.org/stable/c/08bed2b67d2ee79d3e138c344d8dcfa4c9b26a38
- https://git.kernel.org/stable/c/514a5d42d4188fc5f1499a8d654c717ebf981193
- https://git.kernel.org/stable/c/63320a0f70f66f311f4bccff3af0719c2119f46c
- https://git.kernel.org/stable/c/6401b99a285cd4cfb2949ba44675541b91ad7e4f
- https://git.kernel.org/stable/c/e270d539b8a2e0cb8f617fee47a7b083c0088361
- https://git.kernel.org/stable/c/e4c05ebd01e910bccd4f7e9517c7353982e27763
- https://git.kernel.org/stable/c/ed8bfb43de71213cfdbbe833b2c2817250e18b1a
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80534",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"lessThan": "e4c05ebd01e910bccd4f7e9517c7353982e27763",
"versionType": "git"
},
{
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"lessThan": "6401b99a285cd4cfb2949ba44675541b91ad7e4f",
"versionType": "git"
},
{
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"lessThan": "0865e4fca02e418fd2423fae9a887dee87b778a1",
"versionType": "git"
},
{
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"lessThan": "ed8bfb43de71213cfdbbe833b2c2817250e18b1a",
"versionType": "git"
},
{
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"lessThan": "e270d539b8a2e0cb8f617fee47a7b083c0088361",
"versionType": "git"
},
{
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"lessThan": "514a5d42d4188fc5f1499a8d654c717ebf981193",
"versionType": "git"
},
{
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"lessThan": "08bed2b67d2ee79d3e138c344d8dcfa4c9b26a38",
"versionType": "git"
},
{
"status": "affected",
"version": "bda250dbaf39f67f8910e183853e4e6a9e5ce899",
"lessThan": "63320a0f70f66f311f4bccff3af0719c2119f46c",
"versionType": "git"
}
],
"programFiles": [
"fs/xfs/xfs_dquot.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/xfs/xfs_dquot.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-26T15:17:07.530",
"references": [
{
"url": "https://git.kernel.org/stable/c/0865e4fca02e418fd2423fae9a887dee87b778a1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/08bed2b67d2ee79d3e138c344d8dcfa4c9b26a38",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/514a5d42d4188fc5f1499a8d654c717ebf981193",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/63320a0f70f66f311f4bccff3af0719c2119f46c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6401b99a285cd4cfb2949ba44675541b91ad7e4f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e270d539b8a2e0cb8f617fee47a7b083c0088361",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e4c05ebd01e910bccd4f7e9517c7353982e27763",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ed8bfb43de71213cfdbbe833b2c2817250e18b1a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix ilock leak on error in xfs_dq_get_next_id\n\nxfs_dq_get_next_id() takes the quota inode ILOCK before calling\nxfs_iread_extents(). If xfs_iread_extents() fails, the function returns\nimmediately without releasing the lock, leaking the quota inode ILOCK.\nThis can leave the quota inode locked and cause subsequent quota\noperations to hang.\n\nFix this by jumping to a common unlock path on error instead of returning\ndirectly."
}
],
"lastModified": "2026-08-27T13:18:38.800",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}