PT-2026-98492 · Linux · Linux
CVE-2026-97552
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
xfs: initialise error in xfs defer finish one()
xfs defer finish one() declares error without an initialiser and only
assigns it inside the loop over dfp->dfp work. When that list is empty
the loop body never runs, control falls through to the "Done with the
dfp, free it" path, and the function returns an indeterminate value.
An item-less pending item reaches this through xfs defer add barrier(),
which xfs reap ag blocks() uses on any CONFIG XFS ONLINE REPAIR kernel.
xfs defer finish noroll() treats any non-EAGAIN return as fatal, so a
non-zero stack value turns a successful barrier into a
SHUTDOWN CORRUPT INCORE in the middle of a repair. Zero is the correct
result: reaching the free path means the item loop drained without a
non-zero error.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux