CVE-2026-64187 Details
Description
In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no regions If the first op of a transaction is a bare transaction header (len == sizeof(struct xfs_trans_header)), xlog_recover_add_to_trans() adds an item but no region, leaving it on r_itemq with ri_cnt == 0 and ri_buf == NULL. The header can be split across op records, so later ops may still add regions; the item is only invalid if the transaction commits with none. The runtime commit path never emits such a transaction, so this only happens on a crafted log. It came from an AI-assisted code audit of the recovery parser. xlog_recover_reorder_trans() calls ITEM_TYPE() on the item, which reads *(unsigned short *)item->ri_buf[0].iov_base and faults on the NULL ri_buf. Reject it there, before the commit handlers that also read ri_buf[0]. KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:xlog_recover_reorder_trans (fs/xfs/xfs_log_recover.c:1836) xlog_recover_commit_trans (fs/xfs/xfs_log_recover.c:2043) xlog_recover_process_data (fs/xfs/xfs_log_recover.c:2501) xlog_do_recovery_pass (fs/xfs/xfs_log_recover.c:3244) xlog_recover (fs/xfs/xfs_log_recover.c:3493) xfs_log_mount (fs/xfs/xfs_log.c:618) xfs_mountfs (fs/xfs/xfs_mount.c:1034) xfs_fs_fill_super (fs/xfs/xfs_super.c:1938) vfs_get_tree (fs/super.c:1695) path_mount (fs/namespace.c:4161) __x64_sys_mount (fs/namespace.c:4367)
A vulnerability in the Linux kernel's XFS file system log recovery process can lead to a null pointer dereference. This issue occurs when a transaction is crafted to include only a bare transaction header, without any associated regions. During the recovery process, the system attempts to process this header as a complete transaction, which can result in a fault when it tries to access the missing data. This vulnerability was introduced in version 4.3 and has been fixed in subsequent releases.
Users can upgrade to the latest version of the Linux kernel to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2094dab19d45c487285617b7b68913d0cc0c1211 | kernel.org | Patch |
| https://git.kernel.org/stable/c/226a3c8bea7163c39fe0a1c0ffc7ab7410ef3ba4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5105426424ad6981db827cc1ada835a488fab035 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cccbabeb9a18fcb978d76d6047f2b59214aa7749 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d0ae7ec3aa61db5140b107f0a63e017f63e56a96 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d50b1fd066d66ceb548ba43e332cfe8a47e5e55a | kernel.org | Patch |
| https://git.kernel.org/stable/c/d98f22d2e11e0a36493aeb25b2933571ee90d9a4 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.3, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 7.2 rc1 7.2 rc2 7.2 rc3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | CVE Modified | kernel.org |
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jul 24, 2026 | CVE Modified | kernel.org |
| Jul 20, 2026 | New CVE Received | kernel.org |