CVE-2026-80535

Source
https://cve.org/CVERecord?id=CVE-2026-80535
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80535.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80535
Downstream
Published
2026-08-26T14:37:10.985Z
Modified
2026-08-28T11:48:23.512244864Z
Summary
xfs: don't double-lock when deleting a self-referential directory
Details

In the Linux kernel, the following vulnerability has been resolved:

xfs: don't double-lock when deleting a self-referential directory

LOLLM notices that the dirtree scrubber can detect a directory that refers to itself. In this case, it's not correct for the directory tree repair code to try to iolock/ilock both sc->ip and dp, because they're the same inode. Fix this by detecting that corner case and handling it appropriately.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80535.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3f31406aef493b3f19020909d29974e28253f91c
Fixed
17bc347cbdfb125eddac0a815b1f6c1f6eb56676
Fixed
ce2a7006ec5ed88db1b1669124ec85bc1714ccaa
Fixed
c575904471570e69bce40fa638365c6c0403e2ff
Fixed
5fc643fb86599e29b38e7b2c2680b4b15bf8f772

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80535.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80535.json"