Bug 2541142 (CVE-2026-97548) - CVE-2026-97548 kernel: xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
Summary: CVE-2026-97548 kernel: xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk f...
Keywords:
Status: NEW
Alias: CVE-2026-97548
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 10:51 UTC by OSIDB Bzimport
Modified: 2026-09-28 23:04 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 10:51:47 UTC
In the Linux kernel, the following vulnerability has been resolved:

xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions

The _maxlevels_ondisk functions are used to compute the size of
in-memory btree cursors for each btree type.  Unfortunately, LOLLM
noticed that the rtrmap and rtrefcount versions of these functions
forget to account for the inode root, which means that we could access
beyond the end of the cursor given a sufficiently large btree.  Fix
this.


Note You need to log in before you can comment on or make changes to this bug.