CVE-2026-97547
Received Received - Intake

XFS Filesystem Reflink Flag Corruption Issue

Vulnerability report for CVE-2026-97547, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN When exchanging two full-file ranges, xmi_can_exchange_reflink_flags() can move the reflink inode flag from the file that currently has it to the other file, as long as exactly one side is marked. This assumes that the file contents, and therefore all shared extents, are exchanged. That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set. xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings from file1, so an exchange can complete without moving every mapping that the earlier flag-swap decision accounted for. In that case the post-operation cleanup can clear the reflink flag from an inode that still owns shared written extents. Later writes then take the non-reflink write path and may update blocks that should still have been protected by CoW, which shows up as data corruption between reflink-related files. Fix this by disabling the reflink flag exchange whenever XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still proceed; the conservative outcome is that both inodes keep the reflink flag. The regular reflink flag cleanup path can drop the extra flag later once the inode no longer has shared extents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves an issue with the XFS file system when exchanging two full-file ranges. The problem occurs when reflink inode flags are moved between files during an exchange operation. If certain conditions are met, the cleanup process may incorrectly clear the reflink flag from an inode that still owns shared written extents. This can lead to data corruption as later writes may update blocks that should remain protected by copy-on-write (CoW).

Impact Analysis

This vulnerability can cause data corruption between files that use reflink features. If you rely on XFS with reflink functionality, affected systems may experience silent data corruption, leading to inconsistencies in files that share extents. This could result in application errors, file system inconsistencies, or loss of data integrity.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve the XFS reflink flag clearing issue. Monitor file integrity for corruption between reflink-related files after applying updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97547. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart