All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80805: xfs: validate attr entry pointer before field access
@ 2026-09-04 15:11 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:11 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

xfs: validate attr entry pointer before field access

xfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen,
valuelen) before checking if the entry pointer itself is within bounds.
If nameidx is crafted to point near the end of the buffer, these field
accesses can read out-of-bounds before the bounds check at
name_end > buf_end is performed.

Add explicit bounds checks for entry pointers before accessing their
fields. Use offsetof() to check that the start of the flexible array
member (nameval/name) is within bounds, which ensures all preceding
fields are safe to access.

The Linux kernel CVE team has assigned CVE-2026-80805 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.5 with commit c84760659dcf237902d4cc997cd5f55cb3b2807f and fixed in 5.10.267 with commit 0f82586741e39926542f621bafa424e237a04fa4
	Issue introduced in 5.5 with commit c84760659dcf237902d4cc997cd5f55cb3b2807f and fixed in 5.15.218 with commit 134d82a2b5e3eba3ebf58753a1387b22f26ca1de
	Issue introduced in 5.5 with commit c84760659dcf237902d4cc997cd5f55cb3b2807f and fixed in 6.1.185 with commit 03a12253dd2a036545bdb0110a4e0b8dc70f8e7c
	Issue introduced in 5.5 with commit c84760659dcf237902d4cc997cd5f55cb3b2807f and fixed in 6.6.154 with commit e99120b5944a16d0bc27e52b33de78bcdaaabf5c
	Issue introduced in 5.5 with commit c84760659dcf237902d4cc997cd5f55cb3b2807f and fixed in 6.12.106 with commit 98a42bb9d60d42898c3494de351a1bf508348cde
	Issue introduced in 5.5 with commit c84760659dcf237902d4cc997cd5f55cb3b2807f and fixed in 6.18.47 with commit 184c1a80421a5b5ddcd262e47980ce2e67fee211
	Issue introduced in 5.5 with commit c84760659dcf237902d4cc997cd5f55cb3b2807f and fixed in 7.1.11 with commit 9f92e749fc08b7ff3d9da190c4d1b2273745b282
	Issue introduced in 5.5 with commit c84760659dcf237902d4cc997cd5f55cb3b2807f and fixed in 7.2.1 with commit c35da2bac6f7cb9a9be73f188b4fcc324615c327
	Issue introduced in 5.5 with commit c84760659dcf237902d4cc997cd5f55cb3b2807f and fixed in 7.3-rc1 with commit b7eea80be25f3334f131d52982b3131aba77b97d

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80805
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/xfs/libxfs/xfs_attr_leaf.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/0f82586741e39926542f621bafa424e237a04fa4
	https://git.kernel.org/stable/c/134d82a2b5e3eba3ebf58753a1387b22f26ca1de
	https://git.kernel.org/stable/c/03a12253dd2a036545bdb0110a4e0b8dc70f8e7c
	https://git.kernel.org/stable/c/e99120b5944a16d0bc27e52b33de78bcdaaabf5c
	https://git.kernel.org/stable/c/98a42bb9d60d42898c3494de351a1bf508348cde
	https://git.kernel.org/stable/c/184c1a80421a5b5ddcd262e47980ce2e67fee211
	https://git.kernel.org/stable/c/9f92e749fc08b7ff3d9da190c4d1b2273745b282
	https://git.kernel.org/stable/c/c35da2bac6f7cb9a9be73f188b4fcc324615c327
	https://git.kernel.org/stable/c/b7eea80be25f3334f131d52982b3131aba77b97d

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-04 15:17 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:11 CVE-2026-80805: xfs: validate attr entry pointer before field access Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.