CVE-2026-23223
HIGHLinux Kernel < 6.12.72, 6.13.0-6.18.10, 6.19.0, 6.9.0-6.12.71 - Use-After-Free in xfs_btree_check_block_owner
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: xfs: fix UAF in xchk_btree_check_block_owner We cannot dereference bs->cur when trying to determine if bs->cur aliases bs->sc->sa.{bno,rmap}_cur after the latter has been freed. Fix this by sampling before type before any freeing could happen. The correct temporal ordering was broken when we removed xfs_btnum_t.
References (4)
Core 4
Core References
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
4.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (16)
linux/Kernel
< 6.12.72linux
linux/Kernel
6.13.0 - 6.18.11linux
linux/Kernel
6.19.0 - 6.19.1linux
linux/Kernel
6.9.0 - 6.12.72linux
Linux/Linux
< 6.9
Linux/Linux
6.12.72 - 6.12.*
Linux/Linux
6.18.11 - 6.18.*
Linux/Linux
6.19.1 - 6.19.*
Linux/Linux
6.9
Linux/Linux
7.0
... and 6 more
Published
Feb 18, 2026
Tracked Since
Feb 18, 2026