CVE-2026-64256: xfs: don't wrap around quota ids in dqiterate
In the Linux kernel, the following vulnerability has been resolved:
xfs: don't wrap around quota ids in dqiterate
LOLLM noticed that qid is an unsigned 32-bit variable. If it happens to be set to XFSDQIDMAX due to a filesystem that actually has a dquot for IDMAX, then this addition will truncate to zero and the iteration starts over. Fix this by casting to u64.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If q_id handling is affected in dqiterate for XFS, ensure the code path casts the unsigned 32-bit q_id to u64 to prevent wrap-around/truncation behavior (e.g., in the dqiterate iteration over quota ids).