Impact
The vulnerability is a null‑pointer dereference in the XFS log recovery code. A crafted recovery log can contain a transaction header that the system interprets as a log item with no regions, causing xlog_recover_reorder_trans to dereference a NULL ri_buf and trigger a kernel crash. The consequence is a denial‑of‑service event that may bring the system to a halt, but it does not provide code execution or compromise of confidentiality.
Affected Systems
All Linux kernel installations that use the XFS filesystem are affected. The issue resides in the core XFS code (fs/xfs/xfs_log_recover.c) and applies to any kernel version that includes the unpatched XFS implementation. Vendor notes list Linux:Linux, which means the fix is bundled in subsequent kernel releases.
Risk and Exploitability
The vulnerability has a medium severity score (CVSS 5.5) due to a kernel panic. Exploitation requires a crafted XFS log or an attacker who can influence the XFS journal, which implies local or root‑level access or the ability to forge a file system image. As there is no remote trigger, the attack vector is unlikely from the network. The EPSS score is < 1%, and the vulnerability is not currently listed in the CISA KEV catalog, but a kernel crash remains a significant issue.
OpenCVE Enrichment
Debian DLA
Debian DSA