Junglewise Threat Intelligence

CVE-2026-64356: Linux Kernel memory leak in XFS xfs_dqinode_metadir_create

CVE-2026-64356 · Severity: info · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's XFS file system could allow a local user to cause a memory leak. This occurs when the system fails to properly clean up resources during certain file system operations, specifically when managing disk quotas. Over time, this could lead to system instability or a denial of service as available memory is exhausted.

Technical details

A memory leak exists in the xfs_dqinode_metadir_create() function within the XFS file system implementation. When xfs_metadir_create() or a subsequent commit fails, the kernel fails to release allocated update and transaction states, and may leave behind caller-owned inode references. An attacker with local access could potentially trigger these failure paths (e.g., through specific mount options like 'uquota' on a crafted metadir XFS image) to exhaust kernel memory. The issue was identified in versions ranging from v6.13-rc1 to v7.1.1 and has been resolved by routing failure paths through xfs_metadir_cancel() and ensuring proper inode release.

Affected products

  • Linux Linux Kernel 6.13 through 7.1.1

Timeline

  • 2026-07-25: advisory: NVD publication date
  • 2026-07-25: patched: Kernel stable tree updates published

References

Related threats