CVE-2026-80530

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/08/2026
Last modified:
27/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN<br /> <br /> When exchanging two full-file ranges, xmi_can_exchange_reflink_flags()<br /> can move the reflink inode flag from the file that currently has it to<br /> the other file, as long as exactly one side is marked. This assumes<br /> that the file contents, and therefore all shared extents, are exchanged.<br /> <br /> That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set.<br /> xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings<br /> from file1, so an exchange can complete without moving every mapping<br /> that the earlier flag-swap decision accounted for. In that case the<br /> post-operation cleanup can clear the reflink flag from an inode that<br /> still owns shared written extents. Later writes then take the<br /> non-reflink write path and may update blocks that should still have<br /> been protected by CoW, which shows up as data corruption between<br /> reflink-related files.<br /> <br /> Fix this by disabling the reflink flag exchange whenever<br /> XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still<br /> proceed; the conservative outcome is that both inodes keep the reflink<br /> flag. The regular reflink flag cleanup path can drop the extra flag<br /> later once the inode no longer has shared extents.