CVE-2026-80530
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/08/2026
Last modified:
27/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN<br />
<br />
When exchanging two full-file ranges, xmi_can_exchange_reflink_flags()<br />
can move the reflink inode flag from the file that currently has it to<br />
the other file, as long as exactly one side is marked. This assumes<br />
that the file contents, and therefore all shared extents, are exchanged.<br />
<br />
That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set.<br />
xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings<br />
from file1, so an exchange can complete without moving every mapping<br />
that the earlier flag-swap decision accounted for. In that case the<br />
post-operation cleanup can clear the reflink flag from an inode that<br />
still owns shared written extents. Later writes then take the<br />
non-reflink write path and may update blocks that should still have<br />
been protected by CoW, which shows up as data corruption between<br />
reflink-related files.<br />
<br />
Fix this by disabling the reflink flag exchange whenever<br />
XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still<br />
proceed; the conservative outcome is that both inodes keep the reflink<br />
flag. The regular reflink flag cleanup path can drop the extra flag<br />
later once the inode no longer has shared extents.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH



