Executive brief
A vulnerability in the Linux kernel's XFS file system could allow a user to crash the system or potentially gain unauthorized access to data. The issue occurs when the system manages 'extended attributes,' which are extra pieces of information attached to files. If an attacker can trigger specific file operations, they could cause the file system to shut down or corrupt memory, leading to a total service outage or data loss.
Technical details
A CWE-787 (Out-of-bounds Write) vulnerability exists in the XFS file system component of the Linux kernel. The root cause is an incorrect adjustment of the freemap array in xfs_attr3_leaf_add_work when adding extended attributes (xattrs) to leaf blocks. Specifically, when the entries array grows, the code fails to properly update all freemap entries that might collide with the new array boundaries. This leads to an inconsistent state where the entries array and free space overlap, triggering kernel assertions and subsequent file system shutdowns. An attacker with low privileges could exploit this via network-reachable services that allow setting file attributes, potentially achieving arbitrary code execution or causing a denial of service. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 2.6.12 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-01-23: other: Patch authored by Darrick J. Wong
- 2026-05-06: advisory: CVE-2026-43158 published
References
- https://git.kernel.org/stable/c/24ce71852f2cee6581e2cbebc15489ed52bf63b7
- https://git.kernel.org/stable/c/38613c01f69e1e77e6b8acab1e8ac665d01c2f15
- https://git.kernel.org/stable/c/3eefc0c2b78444b64feeb3783c017d6adc3cd3ce
- https://git.kernel.org/stable/c/43f3b18679615a93bd848afde3602ba160637a46
- https://git.kernel.org/stable/c/6a8737afbccc340e718e0b22577312826390be8b
- https://git.kernel.org/stable/c/a396b3d73d51355e50acdb403ba9c4cae4c1174e
- https://git.kernel.org/stable/c/d08976725355b9d54d8332fce223fa281cc304a5