In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no regions If the first op of a… (CVE-2026-64187)
A vulnerability in the Linux kernel's XFS filesystem recovery code allows a null pointer dereference during log recovery if a crafted transaction log contains a committed log item with no regions. This occurs when the first operation of a transaction is a bare transaction header without associated regions, leading to a null pointer read in the recovery process. The issue arises only from crafted logs and not from normal runtime commits.
AI Analysis
Technical Summary
The Linux kernel XFS filesystem recovery code had a flaw where a committed log item with no regions could cause a null pointer dereference during recovery. Specifically, if the first operation of a transaction is a bare transaction header (with length equal to the size of the transaction header struct), the recovery function xlog_recover_add_to_trans() adds an item without any region, leaving it on the recovery item queue with a null buffer pointer. Later, the function xlog_recover_reorder_trans() attempts to read from this null buffer, causing a fault. This vulnerability only occurs with crafted log data, as the normal commit path never produces such transactions. The issue was discovered via an AI-assisted code audit and fixed by rejecting such invalid items early in the recovery process.
Potential Impact
The vulnerability can cause a null pointer dereference in the kernel during XFS log recovery, potentially leading to a denial of service (system crash) when mounting or recovering the filesystem with a maliciously crafted log. There is no indication of code execution or privilege escalation. The fault occurs only if the filesystem log is crafted to trigger this condition, which is not possible through normal operation.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel source to reject committed log items with no regions during recovery, preventing the null pointer dereference. Since no explicit patch links or vendor advisory are provided, users should apply the latest Linux kernel updates that include this fix. Patch status is not yet confirmed in this data; check the official Linux kernel advisories or trusted sources for the current remediation status.
In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no regions If the first op of a… (CVE-2026-64187)
Description
A vulnerability in the Linux kernel's XFS filesystem recovery code allows a null pointer dereference during log recovery if a crafted transaction log contains a committed log item with no regions. This occurs when the first operation of a transaction is a bare transaction header without associated regions, leading to a null pointer read in the recovery process. The issue arises only from crafted logs and not from normal runtime commits.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel XFS filesystem recovery code had a flaw where a committed log item with no regions could cause a null pointer dereference during recovery. Specifically, if the first operation of a transaction is a bare transaction header (with length equal to the size of the transaction header struct), the recovery function xlog_recover_add_to_trans() adds an item without any region, leaving it on the recovery item queue with a null buffer pointer. Later, the function xlog_recover_reorder_trans() attempts to read from this null buffer, causing a fault. This vulnerability only occurs with crafted log data, as the normal commit path never produces such transactions. The issue was discovered via an AI-assisted code audit and fixed by rejecting such invalid items early in the recovery process.
Potential Impact
The vulnerability can cause a null pointer dereference in the kernel during XFS log recovery, potentially leading to a denial of service (system crash) when mounting or recovering the filesystem with a maliciously crafted log. There is no indication of code execution or privilege escalation. The fault occurs only if the filesystem log is crafted to trigger this condition, which is not possible through normal operation.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel source to reject committed log items with no regions during recovery, preventing the null pointer dereference. Since no explicit patch links or vendor advisory are provided, users should apply the latest Linux kernel updates that include this fix. Patch status is not yet confirmed in this data; check the official Linux kernel advisories or trusted sources for the current remediation status.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5fjh-93mh-6xvw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64187"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5e79e92a4a8d59899bad5c
Added to database: 07/20/2026, 19:41:29 UTC
Last enriched: 07/20/2026, 19:44:46 UTC
Last updated: 07/21/2026, 05:06:14 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.