CVE-2026-64256: xfs: don't wrap around quota ids in dqiterate
In the Linux kernel, the following vulnerability has been resolved:
xfs: don't wrap around quota ids in dqiterate
LOLLM noticed that qid is an unsigned 32-bit variable. If it happens to be set to XFSDQIDMAX due to a filesystem that actually has a dquot for IDMAX, then this addition will truncate to zero and the iteration starts over. Fix this by casting to u64.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If q_id handling is affected in dqiterate for XFS, ensure the code path casts the unsigned 32-bit q_id to u64 to prevent wrap-around/truncation behavior (e.g., in the dqiterate iteration over quota ids).
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Affected systems are Linux kernel hosts using XFS quota iteration where the filesystem contains a dquot with the maximum quota ID value, XFS_DQ_ID_MAX. The provided data does not establish whether this condition can occur in a default configuration.
What level of access is required to exploit it?
The CVSS vector indicates local access and low privileges are required, with no user interaction. The reported impact is limited to availability; no confidentiality or integrity impact is indicated.
How can I check whether a fix is present?
Check whether the kernel includes one of the referenced stable commits: 249e311c2ba392ceaf9ebfc145a46922946f069a, d1c4c40599c376aeb0c93068a2ae344e79ee4b90, or 2b14fe1e0924c6b901f4256456342569c5397abe. The supplied information does not map these commits to specific kernel release versions.