Answer in brief
CVE-2026-80536 records a High severity (CVSS 8.4) vulnerability in xfs: bounds-check buffer log item's dirty bitmap. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f8288214459ead7e87d26e5822f62c14a4f2ed6b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <edaf5b6bd625356893da20d69a259b34a9de2694 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <813f8136a2ce1fee266d02a7df73db6e8a541604 | f8288214459ead7e87d26e5822f62c14a4f2ed6b, edaf5b6bd625356893da20d69a259b34a9de2694, 813f8136a2ce1fee266d02a7df73db6e8a541604 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <acb4e26295e7f0e685815a3fd3d70bd8329cefa1 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f3859c35a4fbc1c1c58431f684f808e43696891d || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f7b5fa83e2c192be922121b764415fa8c7549ea1 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b7528b42813f02724a78fce1da24d69d1bfc4d38 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7e32d4eebae6ca24f8a673c107fd7eca1f47afc2 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f8288214459ead7e87d26e5822f62c14a4f2ed6b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <edaf5b6bd625356893da20d69a259b34a9de2694 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <813f8136a2ce1fee266d02a7df73db6e8a541604 | acb4e26295e7f0e685815a3fd3d70bd8329cefa1, f3859c35a4fbc1c1c58431f684f808e43696891d, f7b5fa83e2c192be922121b764415fa8c7549ea1, b7528b42813f02724a78fce1da24d69d1bfc4d38, 7e32d4eebae6ca24f8a673c107fd7eca1f47afc2, f8288214459ead7e87d26e5822f62c14a4f2ed6b, edaf5b6bd625356893da20d69a259b34a9de2694, 813f8136a2ce1fee266d02a7df73db6e8a541604 |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
In the Linux kernel, the following vulnerability has been resolved: xfs: bounds-check buffer log item's dirty bitmap xlog_recover_do_reg_buffer() replays each dirty region described by a buffer log item's bitmap into the buffer read for that item: memcpy(xfs_buf_offset(bp, (uint)bit << XFS_BLF_SHIFT), item->ri_buf[i].iov_base, nbits << XFS_BLF_SHIFT); The destination offset (bit/nbits, from the logged dirty bitmap) and the buffer size (from the logged blf_len) are both attacker-controlled and otherwise unrelated, yet the only thing bounding the copy is an ASSERT(), which compiles away on production kernels. A crafted image logging a small blf_len together with a bitmap bit past the end of that buffer drives the memcpy() past the buffer's allocation, corrupting adjacent kernel heap during mount-time log recovery. This is reachable by anyone who can get a crafted image mounted -- the malicious-filesystem threat model XFS already guards against elsewhere. Turn the ASSERT() into a real XFS_IS_CORRUPT() check that aborts recovery of the buffer with -EFSCORRUPTED, consistent with the validate-and-fail idiom already used in xlog_recover_do_inode_buffer() and xfs_dquot_item_recover.c. xlog_recover_do_reg_buffer() therefore becomes STATIC int and its three callers propagate the error. Found and confirmed with KASAN on a CONFIG_XFS_DEBUG=n build: the crafted image trips a slab-out-of-bounds write before this change and fails recovery cleanly with -EFSCORRUPTED after it.
Quoted source text, attributed separately from HOL analysis.