Executive brief
A vulnerability was identified in the Linux kernel's XFS file system component during the process of unmounting a drive. If exploited, this flaw could lead to system instability or unauthorized access to data by causing the system to handle memory incorrectly. This issue primarily affects systems using the XFS file system and could potentially be used by a local attacker to crash the system or escalate privileges.
Technical details
A vulnerability exists in the XFS file system's unmount sequence within the xfs_unmount_flush_inodes() function. The root cause is a race condition where the Active Item List (AIL) is pushed while background reclaim and inode garbage collection (inodegc) are still active. This allows inodegc to dirty and insert inodes into the AIL during a flush, or background reclaim to abort and free dirty inodes, potentially leading to a use-after-free (CWE-416) scenario. A local attacker can exploit this to cause a denial of service or achieve elevated privileges. The fix involves reordering the unmount sequence to stop inodegc and cancel background reclaim before the AIL is pushed.
Affected products
- Linux Linux Kernel 5.9 to 5.10.253, 5.11 to 5.15.203, 5.16 to 6.1.168, 6.2 to 6.6.131, 6.7 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11
Timeline
- 2026-03-10: other: Patch authored
- 2026-04-22: advisory: CVE published
References
- https://git.kernel.org/stable/c/239d734c00644072862fa833805c4471573b1445
- https://git.kernel.org/stable/c/4f24a767e3d64a5f58c595b5c29b6063a201f1e3
- https://git.kernel.org/stable/c/558e3275d8a3b101be18a7fe7d1634053e9d9b07
- https://git.kernel.org/stable/c/8147e304d7d32fd5c3e943babc296ce2873dc279
- https://git.kernel.org/stable/c/a89434a6188d8430ea31120da96e3e4cefb58686
- https://git.kernel.org/stable/c/bda27fc0b4eb3a425d9a18475c4cb94fbe862c60
- https://git.kernel.org/stable/c/d38135af04a3ad8a585c899d176efc8e97853115