CVE Database
/

CVE-2026-43063

Back to search

CVE-2026-43063

Published: May 5, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: xfs: don't irele after failing to iget in xfs_attri_recover_work xlog_recovery_iget* never set @ip to a valid pointer if they return an error, so this irele will walk off a dangling pointer. Fix that.

VendorProductVersions

Linux

Linux

affected
ae673f534a30976ce5e709c4535a59c12b786ef3 - < b5c5a50c2f513d4a13a6763564a07b470e69cc5a
affected
ae673f534a30976ce5e709c4535a59c12b786ef3 - < a1a5df1038f0b3c560d204270373621a4e622808
affected
ae673f534a30976ce5e709c4535a59c12b786ef3 - < 40082d08b638485cbaa543dc8087a3d1844d6f08
affected
ae673f534a30976ce5e709c4535a59c12b786ef3 - < 70685c291ef82269180758130394ecdc4496b52c

Linux

Linux

affected
6.10
unaffected
0 - < 6.10
unaffected
6.12.80 - <= 6.12.*
unaffected
6.18.21 - <= 6.18.*
unaffected
6.19.11 - <= 6.19.*

+1 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now