CVE-2026-45861: gfs2: Fix slab-use-after-free in qd_put
Published May 27, 2026
·Updated
gfs2: Fix slab-use-after-free in qdput
Affected Software
4 affected components
Linux Linux kernel
Linux Linux kernel>=6.6<6.12.75
Linux Linux kernel>=6.13<6.18.14
Linux Linux kernel>=6.19<6.19.4
Event History
May 27, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverity
Data Sourced
via NVD·02:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 28, 2026
Data Sourced
via Microsoft·08:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Linux systems using the GFS2 filesystem are relevant. The vulnerable path involves GFS2 quota-data handling during filesystem shutdown and the GFS2 shrinker.
2
What access does an attacker need?
The CVSS vector indicates local access and low privileges are required. No user interaction is required.
3
What is the potential impact if exploitation succeeds?
The reported impact includes high confidentiality, integrity, and availability impact. The underlying condition is a use-after-free caused by stale quota-data objects remaining on an LRU list.