Executive brief
A vulnerability was identified in the Linux kernel's XFS file system component. XFS is a high-performance file system used to manage data storage on many Linux servers. An exploit could allow a local user to cause system instability or potentially gain unauthorized access to data by triggering improper memory management during file attribute operations.
Technical details
A vulnerability exists in the XFS file system's attribute management logic due to a problematic calling convention in the xfs_attr_leaf_hasname() function. The function could return a non-NULL pointer to a buffer that had already been released (use-after-free) if xfs_attr3_leaf_lookup_int failed with specific error codes. This flaw allows a local attacker with standard user privileges to trigger memory corruption. The issue was resolved by removing the problematic function and open-coding the logic into its callers to ensure proper buffer lifecycle management. Patches have been released for multiple stable kernel branches including 6.12.y, 6.18.y, and 6.19.y.
Affected products
- Linux Linux kernel 5.9 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: advisory: Initial disclosure of CVE-2026-43153
- 2026-01-09: patched: Fix authored by Christoph Hellwig