PT-2026-36470 · Linux · Linux Kernel

CVE-2026-43053

·

Published

2026-03-17

·

Updated

2026-08-30

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the XFS file system during the inactivation of an inode with node-format extended attributes. The function xfs attr3 node inactive() invalidates child leaf or node blocks using xfs trans binval() but does not immediately remove the corresponding entries from parent node blocks. If a log shutdown occurs after these cancellations commit but before the attribute block map (bmap) truncation commits, log recovery may leave stale data on disk. Upon the next mount, xlog recover process iunlinks() may attempt to read the root node via the bmap, leading to a metadata verification failure in xfs da3 node read verify() or when following child pointers to unreplayed blocks, resulting in a metadata corruption shutdown.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-85347
BDU:2026-07838
CVE-2026-43053
OESA-2026-2418
OESA-2026-2492
OESA-2026-2493
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22436-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22460-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1

Affected Products

Linux Kernel