CVE-2026-64187
CVE CVE-2026-64187EUVD EUVD-2026-46007Veröffentlicht 2026-07-20T16:27:46.000ZZuletzt geändert 2026-07-24T14:34:17.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no regions If the first op of a transaction is a bare transaction header (len == sizeof(struct xfs_trans_header)), xlog_recover_add_to_trans() adds an item but no region, leaving it on r_itemq with ri_cnt == 0 and ri_buf == NULL. The header can be split across op records, so later ops may still add regions; the item is only invalid if the transaction commits with none. The runtime commit path never emits such a transaction, so this only happens on a crafted log. It came from an AI-assisted code audit of the recovery parser. xlog_recover_reorder_trans() calls ITEM_TYPE() on the item, which reads *(unsigned short *)item->ri_buf[0].iov_base and faults on the NULL ri_buf. Reject it there, before the commit handlers that also read ri_buf[0]. KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:xlog_recover_reorder_trans (fs/xfs/xfs_log_recover.c:1836) xlog_recover_commit_trans (fs/xfs/xfs_log_recover.c:2043) xlog_recover_process_data (fs/xfs/xfs_log_recover.c:2501) xlog_do_recovery_pass (fs/xfs/xfs_log_recover.c:3244) xlog_recover (fs/xfs/xfs_log_recover.c:3493) xfs_log_mount (fs/xfs/xfs_log.c:618) xfs_mountfs (fs/xfs/xfs_mount.c:1034) xfs_fs_fill_super (fs/xfs/xfs_super.c:1938) vfs_get_tree (fs/super.c:1695) path_mount (fs/namespace.c:4161) __x64_sys_mount (fs/namespace.c:4367)
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 89cebc8477290b152618ffa110bbeae340d50900 <2094dab19d45c487285617b7b68913d0cc0c1211; patch: 7.2-rc4; patch: 0; patch: 6.18.39; patch: 7.1.4; 4.3; 89cebc8477290b152618ffa110bbeae340d50900 <226a3c8bea7163c39fe0a1c0ffc7ab7410ef3ba4; 89cebc8477290b152618ffa110bbeae340d50900 <d50b1fd066d66ceb548ba43e332cfe8a47e5e55a; patch: 5.15.212; 89cebc8477290b152618ffa110bbeae340d50900 <cccbabeb9a18fcb978d76d6047f2b59214aa7749; patch: 6.6.145; patch: 6.1.178; 89cebc8477290b152618ffa110bbeae340d50900 <d98f22d2e11e0a36493aeb25b2933571ee90d9a4; patch: 6.12.96; 89cebc8477290b152618ffa110bbeae340d50900 <d0ae7ec3aa61db5140b107f0a63e017f63e56a96; 89cebc8477290b152618ffa110bbeae340d50900 <5105426424ad6981db827cc1ada835a488fab035
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.