In the Linux kernel, the following vulnerability has been resolved:
xfs: bounds-check buffer log item's dirty bitmap
xlog_recover_do_reg_buffer() replays each dirty region described by a buffer log item's bitmap into the buffer read for that item:
memcpy(xfs_buf_offset(bp, (uint)bit << XFS_BLF_SHIFT), item->ri_buf[i].iov_base, nbits << XFS_BLF_SHIFT);
The destination offset (bit/nbits, from the logged dirty bitmap) and the buffer size (from the logged blf_len) are both attacker-controlled and otherwise unrelated, yet the only thing bounding the copy is an ASSERT(), which compiles away on production kernels. A crafted image logging a small blf_len together with a bitmap bit past the end of that buffer drives the memcpy() past the buffer's allocation, corrupting adjacent kernel heap during mount-time log recovery. This is reachable by anyone who can get a crafted image mounted -- the malicious-filesystem threat model XFS already guards against elsewhere.
Turn the ASSERT() into a real XFS_IS_CORRUPT() check that aborts recovery of the buffer with -EFSCORRUPTED, consistent with the validate-and-fail idiom already used in xlog_recover_do_inode_buffer() and xfs_dquot_item_recover.c. xlog_recover_do_reg_buffer() therefore becomes STATIC int and its three callers propagate the error.
Found and confirmed with KASAN on a CONFIG_XFS_DEBUG=n build: the crafted image trips a slab-out-of-bounds write before this change and fails recovery cleanly with -EFSCORRUPTED after it.
CVSS Details
- CVSS 3.1 Base Score: 8.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18Upgrade kernel6.18-toolsUpgrade kernel-livepatch-6.18.48-107.148Upgrade kernel6.18-debuginfoUpgrade kernel6.18-modules-extraUpgrade perf6.18-debuginfoUpgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel6.18-headersUpgrade perf6.18Upgrade python3-perf6.18Upgrade kernel6.18-tools-debuginfoUpgrade kernel6.18-develUpgrade kernel6.18-tools-develUpgrade bpftool6.18Upgrade python3-perf6.18-debuginfoUpgrade kernel6.18-debuginfo-common-x86_64Upgrade bpftool6.18-debuginfoUpgrade microvm-kernel6.18Upgrade kernel6.18-modules-extra-common | Sep 30, 2026 | Aug 26, 2026 |
| Debian | — | Upgrade linuxUpgrade linux-6.12 | Aug 30, 2026 | Aug 30, 2026 |
| Redhat_linux | — | No solution exists | Aug 28, 2026 | Aug 26, 2026 |
| Ubuntu | — | Upgrade linux-image-nvidia-tegra-rtUpgrade linux-image-6.8.0-1036-nvidia-tegraUpgrade linux-image-nvidia-tegraUpgrade linux-image-nvidia-tegra-6.8Upgrade linux-image-6.8.0-1036-nvidia-tegra-rtUpgrade linux-image-nvidia-tegra-rt-6.8 | Oct 7, 2026 | Oct 6, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 15, 2026 | Aug 26, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub