CVE-2026-97548

Source
https://cve.org/CVERecord?id=CVE-2026-97548
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97548.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97548
Downstream
Published
2026-09-25T10:21:42Z
Modified
2026-09-26T03:48:40Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
Details

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions

The _maxlevels_ondisk functions are used to compute the size of in-memory btree cursors for each btree type. Unfortunately, LOLLM noticed that the rtrmap and rtrefcount versions of these functions forget to account for the inode root, which means that we could access beyond the end of the cursor given a sufficiently large btree. Fix this.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97548.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9abe03a0e4f978615a2b1b484b8d09ca84c16ea0
Fixed
108114437915e61e8f88d1cbcc442c3f886a347e
Fixed
84316cb25af95a60e655ccc8fe646bb5ad631b71
Fixed
aa301322f72f82f26e4ba0826018d41388ab9896

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97548.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97548.json"