CVE-2026-80530
Received Received - Intake

XFS Filesystem Reflink Flag Clearing Issue

Vulnerability report for CVE-2026-80530, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN When exchanging two full-file ranges, xmi_can_exchange_reflink_flags() can move the reflink inode flag from the file that currently has it to the other file, as long as exactly one side is marked. This assumes that the file contents, and therefore all shared extents, are exchanged. That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set. xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings from file1, so an exchange can complete without moving every mapping that the earlier flag-swap decision accounted for. In that case the post-operation cleanup can clear the reflink flag from an inode that still owns shared written extents. Later writes then take the non-reflink write path and may update blocks that should still have been protected by CoW, which shows up as data corruption between reflink-related files. Fix this by disabling the reflink flag exchange whenever XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still proceed; the conservative outcome is that both inodes keep the reflink flag. The regular reflink flag cleanup path can drop the extra flag later once the inode no longer has shared extents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_kernel xfs *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves an issue with the XFS file system's reflink feature. When exchanging file ranges between two files, the system may incorrectly clear the reflink flag from an inode that still owns shared written extents. This can lead to data corruption because later writes may update blocks that should remain protected by copy-on-write (CoW).

Detection Guidance

This vulnerability is specific to the XFS filesystem in the Linux kernel and requires kernel-level inspection. Detection involves checking kernel logs for XFS-related errors or corruption events. Use commands like dmesg | grep -i xfs or journalctl -k | grep -i xfs to review filesystem logs. If reflink operations are suspected, monitor for data corruption between files.

Impact Analysis

If you use a Linux system with the XFS file system and reflink feature, this vulnerability could cause data corruption. Files that share extents may become inconsistent, leading to potential loss or corruption of data. Systems relying on reflink for efficient file operations could experience unexpected behavior or crashes.

Mitigation Strategies

Apply the latest kernel update that includes the fix for this issue. If immediate patching is not possible, avoid using reflink operations on XFS filesystems until patched. Review XFS mount options and disable reflink if not required. Monitor filesystem integrity and check for data corruption between reflink-related files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80530. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart