{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80536","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.765Z","datePublished":"2026-08-26T14:37:11.584Z","dateUpdated":"2026-08-27T12:40:04.524Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-27T12:40:04.524Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: bounds-check buffer log item's dirty bitmap\n\nxlog_recover_do_reg_buffer() replays each dirty region described by a\nbuffer log item's bitmap into the buffer read for that item:\n\n\tmemcpy(xfs_buf_offset(bp, (uint)bit << XFS_BLF_SHIFT),\n\t\titem->ri_buf[i].iov_base,\n\t\tnbits << XFS_BLF_SHIFT);\n\nThe destination offset (bit/nbits, from the logged dirty bitmap) and the\nbuffer size (from the logged blf_len) are both attacker-controlled and\notherwise unrelated, yet the only thing bounding the copy is an ASSERT(),\nwhich compiles away on production kernels. A crafted image logging a\nsmall blf_len together with a bitmap bit past the end of that buffer\ndrives the memcpy() past the buffer's allocation, corrupting adjacent\nkernel heap during mount-time log recovery. This is reachable by anyone\nwho can get a crafted image mounted -- the malicious-filesystem threat\nmodel XFS already guards against elsewhere.\n\nTurn the ASSERT() into a real XFS_IS_CORRUPT() check that aborts recovery\nof the buffer with -EFSCORRUPTED, consistent with the validate-and-fail\nidiom already used in xlog_recover_do_inode_buffer() and\nxfs_dquot_item_recover.c. xlog_recover_do_reg_buffer() therefore becomes\nSTATIC int and its three callers propagate the error.\n\nFound and confirmed with KASAN on a CONFIG_XFS_DEBUG=n build: the crafted\nimage trips a slab-out-of-bounds write before this change and fails\nrecovery cleanly with -EFSCORRUPTED after it."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The OOB write is only reachable during XFS log recovery at mount time (mount→xfs_mountfs→xfs_log_mount→xlog_recover→xlog_do_recovery_pass pass2→xlog_recover_buf_commit_pass2→xlog_recover_do_reg_buffer); attacker data comes from a local block/loop device image, not from any network protocol handler.\nAC:L - All trigger fields (blf_len, blf_data_map bit/nbits, and logged source bytes in ri_buf) are attacker-authored on-disk log metadata; pairing a small blf_len with a bitmap region past the buffer end deterministically drives memcpy() past the xfs_buf allocation on every mount with no race or uncontrollable layout.\nPR:N - Mounting the crafted image requires no account or capability on the victim host in the malicious-filesystem threat model: an external attacker only supplies removable media or a disk image and desktop/kiosk udisks2 or systemd automount performs the privileged mount on device insertion without attacker credentials.\nUI:N - Once the crafted XFS volume is presented to the host, log recovery in xlog_recover_do_reg_buffer() runs automatically during mount (including read-only mounts) before any file access; the attacker needs no separate victim to open files, click links, or perform additional actions beyond presenting the image.\nS:U - Heap corruption occurs entirely within the mounting host kernel during log replay; impact is confined to the same kernel security authority and does not cross VM, IOMMU, or container sandbox boundaries.\nC:H - KASAN-confirmed slab-out-of-bounds write corrupts adjacent kernel heap objects; such controlled memory corruption is routinely weaponized for arbitrary kernel read primitives and pointer disclosure, not merely a crash.\nI:H - memcpy() writes attacker-controlled bytes from logged ri_buf regions to attacker-chosen offsets beyond the buffer end, giving a controllable out-of-bounds kernel heap write primitive suitable for control-flow hijacking and privilege escalation.\nA:H - The unchecked memcpy() causes slab-out-of-bounds writes during mount-time recovery (KASAN-verified on CONFIG_XFS_DEBUG=n), reliably corrupting kernel heap and capable of provoking kernel oops/panic or persistent denial of service on repeated mount attempts."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/xfs/xfs_buf_item_recover.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"acb4e26295e7f0e685815a3fd3d70bd8329cefa1","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f3859c35a4fbc1c1c58431f684f808e43696891d","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f7b5fa83e2c192be922121b764415fa8c7549ea1","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b7528b42813f02724a78fce1da24d69d1bfc4d38","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7e32d4eebae6ca24f8a673c107fd7eca1f47afc2","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f8288214459ead7e87d26e5822f62c14a4f2ed6b","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"edaf5b6bd625356893da20d69a259b34a9de2694","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"813f8136a2ce1fee266d02a7df73db6e8a541604","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/xfs/xfs_buf_item_recover.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.267"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.218"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.185"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.154"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.106"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.46"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.1.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/acb4e26295e7f0e685815a3fd3d70bd8329cefa1"},{"url":"https://git.kernel.org/stable/c/f3859c35a4fbc1c1c58431f684f808e43696891d"},{"url":"https://git.kernel.org/stable/c/f7b5fa83e2c192be922121b764415fa8c7549ea1"},{"url":"https://git.kernel.org/stable/c/b7528b42813f02724a78fce1da24d69d1bfc4d38"},{"url":"https://git.kernel.org/stable/c/7e32d4eebae6ca24f8a673c107fd7eca1f47afc2"},{"url":"https://git.kernel.org/stable/c/f8288214459ead7e87d26e5822f62c14a4f2ed6b"},{"url":"https://git.kernel.org/stable/c/edaf5b6bd625356893da20d69a259b34a9de2694"},{"url":"https://git.kernel.org/stable/c/813f8136a2ce1fee266d02a7df73db6e8a541604"}],"title":"xfs: bounds-check buffer log item's dirty bitmap","x_generator":{"engine":"bippy-1.2.0"}}}}