Description
In the Linux kernel, the following vulnerability has been resolved:

xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN

When exchanging two full-file ranges, xmi_can_exchange_reflink_flags()
can move the reflink inode flag from the file that currently has it to
the other file, as long as exactly one side is marked. This assumes
that the file contents, and therefore all shared extents, are exchanged.

That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set.
xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings
from file1, so an exchange can complete without moving every mapping
that the earlier flag-swap decision accounted for. In that case the
post-operation cleanup can clear the reflink flag from an inode that
still owns shared written extents. Later writes then take the
non-reflink write path and may update blocks that should still have
been protected by CoW, which shows up as data corruption between
reflink-related files.

Fix this by disabling the reflink flag exchange whenever
XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still
proceed; the conservative outcome is that both inodes keep the reflink
flag. The regular reflink flag cleanup path can drop the extra flag
later once the inode no longer has shared extents.
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bug in the Linux XFS filesystem incorrectly clears the reflink (copy‑on‑write) flag on an inode during a full‑file range exchange. The logic assumes that all mappings are swapped, but when the XFS_EXCHMAPS_INO1_WRITTEN flag is set, hole and unwritten mappings may be skipped. The flag can then be cleared while the inode still owns shared written extents, causing subsequent writes to bypass copy‑on‑write protection. This leads to corrupted data in reflink‑related files, violating confidentiality and integrity constraints of the affected data.

Affected Systems

The vulnerability resides in the Linux kernel XFS subsystem and is therefore present in any Linux kernel version that contains the legacy code path. No specific version information was provided, so all kernel releases that have not yet applied the commit fixing the issue are potentially affected.

Risk and Exploitability

No EPSS information is available. The vulnerability is not listed in the CISA KEV catalog. The flaw requires manipulating the XFS exchange‑range operation, which is a privileged kernel action typically restricted to users with sufficient filesystem or root privileges. Based on the description, the attack vector is inferred to be a local administrative or root user. While the risk of exploitation is moderate given the need for elevated privileges, the potential for non‑repudiable data corruption is significant.

Generated by OpenCVE AI on August 26, 2026 at 16:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch committing the fix.
  • If a kernel upgrade is not immediately possible, apply the relevant patch to the kernel source tree and rebuild the kernel.
  • After applying the fix, run a filesystem integrity check (e.g., fsck.xfs) on affected XFS volumes to detect any residual corruption.

Generated by OpenCVE AI on August 26, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Wed, 26 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN When exchanging two full-file ranges, xmi_can_exchange_reflink_flags() can move the reflink inode flag from the file that currently has it to the other file, as long as exactly one side is marked. This assumes that the file contents, and therefore all shared extents, are exchanged. That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set. xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings from file1, so an exchange can complete without moving every mapping that the earlier flag-swap decision accounted for. In that case the post-operation cleanup can clear the reflink flag from an inode that still owns shared written extents. Later writes then take the non-reflink write path and may update blocks that should still have been protected by CoW, which shows up as data corruption between reflink-related files. Fix this by disabling the reflink flag exchange whenever XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still proceed; the conservative outcome is that both inodes keep the reflink flag. The regular reflink flag cleanup path can drop the extra flag later once the inode no longer has shared extents.
Title xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-26T14:37:07.990Z

Reserved: 2026-08-26T14:34:25.764Z

Link: CVE-2026-80530

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T15:17:06.990

Modified: 2026-08-26T15:17:06.990

Link: CVE-2026-80530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T18:15:08Z

Weaknesses