← All Advisories

CVE-2026-97547

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97547

Key Details

CVECVE-2026-97547
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN

When exchanging two full-file ranges, xmi_can_exchange_reflink_flags()

can move the reflink inode flag from the file that currently has it to

the other file, as long as exactly one side is marked. This assumes

that the file contents, and therefore all shared extents, are exchanged.

That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set.

xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings

from file1, so an exchange can complete without moving every mapping

that the earlier flag-swap decision accounted for. In that case the

post-operation cleanup can clear the reflink flag from an inode that

still owns shared written extents. Later writes then take the

non-reflink write path and may update blocks that should still have

been protected by CoW, which shows up as data corruption between

reflink-related files.

Fix this by disabling the reflink flag exchange whenever

XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still

proceed; the conservative outcome is that both inodes keep the reflink

flag. The regular reflink flag cleanup path can drop the extra flag

later once the inode no longer has shared extents. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97547
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97547