PT-2026-37493 · Linux+2 · Linux Kernel+2

CVE-2026-43153

·

Published

2026-05-06

·

Updated

2026-08-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A problem exists in the XFS filesystem component where the xfs attr leaf hasname() function has a problematic calling convention. The function may return a NULL buffer if xfs attr3 leaf read() fails, a valid buffer when xfs attr3 leaf lookup int() returns -ENOATTR or -EEXIST, or a non-NULL pointer to an already released buffer when xfs attr3 leaf lookup int() fails with other error values. This behavior involving bad pointers can lead to system instability or crashes.
Recommendations As a temporary workaround, restrict operations that trigger the xfs attr leaf hasname() function until a patch is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-85845
CVE-2026-43153
OESA-2026-2871
OESA-2026-3454
OESA-2026-3455
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu