PT-2026-98492 · Linux · Linux

CVE-2026-97552

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
xfs: initialise error in xfs defer finish one()
xfs defer finish one() declares error without an initialiser and only assigns it inside the loop over dfp->dfp work. When that list is empty the loop body never runs, control falls through to the "Done with the dfp, free it" path, and the function returns an indeterminate value.
An item-less pending item reaches this through xfs defer add barrier(), which xfs reap ag blocks() uses on any CONFIG XFS ONLINE REPAIR kernel. xfs defer finish noroll() treats any non-EAGAIN return as fatal, so a non-zero stack value turns a successful barrier into a SHUTDOWN CORRUPT INCORE in the middle of a repair. Zero is the correct result: reaching the free path means the item loop drained without a non-zero error.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97552

Affected Products

Linux