Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-64187— xfs: fail recovery on a committed log item with no regions

AI Predicted 5.5 Difficulty: Theoretical EPSS 0.16% · P5

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinux89cebc8477290b152618ffa110bbeae340d50900< 5105426424ad6981db827cc1ada835a488fab035affected
89cebc8477290b152618ffa110bbeae340d50900< 226a3c8bea7163c39fe0a1c0ffc7ab7410ef3ba4affected
89cebc8477290b152618ffa110bbeae340d50900< d0ae7ec3aa61db5140b107f0a63e017f63e56a96affected
89cebc8477290b152618ffa110bbeae340d50900< d50b1fd066d66ceb548ba43e332cfe8a47e5e55aaffected
89cebc8477290b152618ffa110bbeae340d50900< d98f22d2e11e0a36493aeb25b2933571ee90d9a4affected
89cebc8477290b152618ffa110bbeae340d50900< cccbabeb9a18fcb978d76d6047f2b59214aa7749affected
89cebc8477290b152618ffa110bbeae340d50900< 2094dab19d45c487285617b7b68913d0cc0c1211affected
4.3affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-64187

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
xfs: fail recovery on a committed log item with no regions
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no regions If the first op of a transaction is a bare transaction header (len == sizeof(struct xfs_trans_header)), xlog_recover_add_to_trans() adds an item but no region, leaving it on r_itemq with ri_cnt == 0 and ri_buf == NULL. The header can be split across op records, so later ops may still add regions; the item is only invalid if the transaction commits with none. The runtime commit path never emits such a transaction, so this only happens on a crafted log. It came from an AI-assisted code audit of the recovery parser. xlog_recover_reorder_trans() calls ITEM_TYPE() on the item, which reads *(unsigned short *)item->ri_buf[0].iov_base and faults on the NULL ri_buf. Reject it there, before the commit handlers that also read ri_buf[0]. KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:xlog_recover_reorder_trans (fs/xfs/xfs_log_recover.c:1836) xlog_recover_commit_trans (fs/xfs/xfs_log_recover.c:2043) xlog_recover_process_data (fs/xfs/xfs_log_recover.c:2501) xlog_do_recovery_pass (fs/xfs/xfs_log_recover.c:3244) xlog_recover (fs/xfs/xfs_log_recover.c:3493) xfs_log_mount (fs/xfs/xfs_log.c:618) xfs_mountfs (fs/xfs/xfs_mount.c:1034) xfs_fs_fill_super (fs/xfs/xfs_super.c:1938) vfs_get_tree (fs/super.c:1695) path_mount (fs/namespace.c:4161) __x64_sys_mount (fs/namespace.c:4367)
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 4.3版本存在安全漏洞,该漏洞源于xfs日志恢复过程中,当事务的第一个操作是裸事务头时,xlog_recover_add_to_trans()添加了一个项目但未添加区域,导致ri_cnt为0且ri_buf为NULL,后续xlog_recover_reorder_trans()读取ri_buf[0]时触发空指针取消引用,可能允许攻击者通过特制日志导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 89cebc8477290b152618ffa110bbeae340d50900 ~ 5105426424ad6981db827cc1ada835a488fab035 -
LinuxLinux 4.3 -

II. Public POCs for CVE-2026-64187

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64187

登录查看更多情报信息。

Patches & Fixes for CVE-2026-64187 (7)

Same Patch Batch · Linux · 2026-07-20 · 9 CVEs total

CVE-2026-64188net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
CVE-2026-64190net: team: fix NULL pointer dereference in team_xmit during mode change
CVE-2026-64189netfilter: ipset: fix race between dump and ip_set_list resize
CVE-2026-64191i2c: stub: Reject I2C block transfers with invalid length
CVE-2026-64192bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
CVE-2026-64205i2c: i801: fix hardware state machine corruption in error path
CVE-2026-64206Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
CVE-2026-64207net/sched: dualpi2: fix GSO backlog accounting

IV. Related Vulnerabilities

V. Comments for CVE-2026-64187

No comments yet


Leave a comment