CVE-2026-97543

Source
https://cve.org/CVERecord?id=CVE-2026-97543
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97543.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97543
Downstream
Published
2026-09-25T10:21:39Z
Modified
2026-09-26T03:48:29Z
Summary
xfs: destroy seen inode bitmap when we fail to add a dirpath
Details

In the Linux kernel, the following vulnerability has been resolved:

xfs: destroy seen inode bitmap when we fail to add a dirpath

LOLLM observes a memory leak in xchk_dirtree_create_path if we create the directory path object but appending the name to the path fails. When this happens, we don't tear down the (empty) seen inode bitmap. This is a pretty trivial error, but let's not leave logic bombs.

Do the same for a similar bug in xrep_dirtree_create_adoption_path.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97543.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
928b721a11789a9363d6d7c32a1f3166a79f3b5f
Fixed
3b10ca4302ee2dda4233f70b2033883ee376fa6a
Fixed
0b756de8167f2f06ffceadc71cb17c1fc7be4be8
Fixed
582f54dce62043f7a0503ab8c76d718d0293da59
Fixed
1a441c6842da75c5b862cc1c9f7969d6a93b54b9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97543.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97543.json"