Executive brief
A vulnerability in the Linux kernel's XFS file system could allow a local user to cause a system crash (kernel oops). The issue occurs when the system incorrectly handles certain disk errors during extended attribute (xattr) lookups, leading to a null pointer dereference. This can result in a denial of service or potentially other system instabilities.
Technical details
A vulnerability exists in the XFS file system component of the Linux kernel where ENODATA (ENOATTR) errors returned from disk media are not properly distinguished from 'attribute not found' status codes. In xfs_attr_leaf_get(), an ENODATA error from the disk can result in a NULL buffer pointer (bp). Subsequent calls to xfs_trans_brelse() with this NULL pointer trigger a null pointer dereference (kernel oops). The fix involves remapping ENODATA errors from lower-level IO functions to EIO to ensure they are handled correctly by higher-level XFS functions. This affects kernels from version 5.9 onwards.
Affected products
- Linux Linux Kernel 5.9 to 5.10.242, 5.11 to 5.15.191, 5.16 to 6.1.150, 6.2 to 6.6.104, 6.7 to 6.12.45, 6.13 to 6.16.5
Timeline
- 2025-08-22: other: Patch authored by Eric Sandeen
- 2025-09-16: disclosed: CVE published
- 2025-09-16: advisory
References
- https://git.kernel.org/stable/c/157ddfb05961c68ab7d457a462822a698e4e4bf4
- https://git.kernel.org/stable/c/39fc2742ca14f7fbc621ce9b43bcbd00248cb9a8
- https://git.kernel.org/stable/c/90bae69c2959c39912f0c2f07a9a7894f3fc49f5
- https://git.kernel.org/stable/c/ae668cd567a6a7622bc813ee0bb61c42bed61ba7
- https://git.kernel.org/stable/c/d3cc7476b89fb45b7e00874f4f56f6b928467c60
- https://git.kernel.org/stable/c/dcdf36f1b67884c722abce9b8946e34ffb9f67c8
- https://git.kernel.org/stable/c/e358d4b6225e4c1eb208686a05e360ef8df59e07