CVE-2026-97551

Source
https://cve.org/CVERecord?id=CVE-2026-97551
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97551.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97551
Downstream
Published
2026-09-25T10:21:44Z
Modified
2026-09-26T03:47:02Z
Summary
xfs: initialise args->total for parent pointer updates
Details

In the Linux kernel, the following vulnerability has been resolved:

xfs: initialise args->total for parent pointer updates

xfs_parent_da_args_init() builds an xfs_da_args from a zeroed xfs_parent_args (kmem_cache_zalloc), leaving args->total == 0. xfs_da_grow_inode_int() treats that field as a running block reservation and subtracts from it; because it is an xfs_extlen_t (uint32_t), the first attr-fork growth wraps it to ~0U. That defeats the free-space check in xfs_alloc_space_available(), and when it coincides with an AG that has exactly zero available blocks the allocation is clamped to maxlen 0 and returns -ENOSPC, which xfs_defer_finish_noroll() escalates to a filesystem shutdown.

Set args->total the way the log recovery path does (xfs_attri_recover_work(), xfs_attr_item.c:706), in the add and replace paths that can grow the fork. Removals and lookups never grow it, so they leave the field alone, matching that switch.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97551.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b7c62d90c12c6cc86f10b8a62cefe0029374b6ff
Fixed
9ad85bce62cadfdf4242f6e6bbff2a52e51d30f1
Fixed
c66e138af626cad4210da449996ae9e07ee63add
Fixed
ac9032882d673dd6679e1d873a2dc0131a1aeb43
Fixed
8e4ebb6afaa34bd2e8ce52da231003d24111c2d6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97551.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97551.json"