PT-2026-34358 · Linux · Linux Kernel

CVE-2026-31453

·

Published

2026-04-22

·

Updated

2026-07-08

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the XFS file system where log items may be dereferenced after push callbacks. Specifically, after the xfsaild push item() function calls iop push(), the log item might have been freed if the AIL lock was dropped during the push process. This can occur during background inode reclaim or the dquot shrinker, leading to a situation where tracepoints in the switch statement attempt to access a freed log item.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31453
ECHO-CA0B-414A-9E9B
OESA-2026-2869
OESA-2026-2871
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22436-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22460-1
SUSE-SU-2026:2722-1
SUSE-SU-2026:2799-1

Affected Products

Linux Kernel