目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-97547— XFS inode交换范围重链接标志清除缺陷

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,已修复以下漏洞: xfs: 修复 INO1_WRITTEN 场景下 exchange-range 操作中 reflink 标志清除的问题 当交换两个完整的文件范围时,函数 可以在恰好仅有一方被标记为 reflink 的情况下,将该 reflink inode 标志从拥有它的文件转移到另一个文件。这一行为基于一个假设:即文件内容(从而所有共享的扩展区 extents)都会被完整交换。 然而,当设置了 标志时,该假设不再成立。此时, 可能会跳过来自 file1 的空洞(hole)或未写入(unw

AI 预测 5.5 利用难度: 中等 EPSS 0.20% · P9

可能的 ATT&CK 技术 1 AI

T1499 · Endpoint Denial of Service

影响版本矩阵 10

厂商产品 版本范围状态
Linux Linux 966ceafc7a437105ecfe1cadb3747b2965a260ca< 56f87ac2b9543be2be529b831666682e6df4bc40 affected
966ceafc7a437105ecfe1cadb3747b2965a260ca< fac32b9950a2aab3f8659d23b2947b8fb305c3fe affected
966ceafc7a437105ecfe1cadb3747b2965a260ca< 8ae30b9a8c207f9bd03a98eda7b5d641daa79bdb affected
966ceafc7a437105ecfe1cadb3747b2965a260ca< a23eca88448e52eb1a81549862df7adce794fafb affected
6.10 affected
< 6.10 unaffected
6.12.111≤ 6.12.* unaffected
6.18.53≤ 6.18.* unaffected
… +2 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-97547 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN When exchanging two full-file ranges, xmi_can_exchange_reflink_flags() can move the reflink inode flag from the file that currently has it to the other file, as long as exactly one side is marked. This assumes that the file contents, and therefore all shared extents, are exchanged. That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set. xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings from file1, so an exchange can complete without moving every mapping that the earlier flag-swap decision accounted for. In that case the post-operation cleanup can clear the reflink flag from an inode that still owns shared written extents. Later writes then take the non-reflink write path and may update blocks that should still have been protected by CoW, which shows up as data corruption between reflink-related files. Fix this by disabling the reflink flag exchange whenever XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still proceed; the conservative outcome is that both inodes keep the reflink flag. The regular reflink flag cleanup path can drop the extra flag later once the inode no longer has shared extents.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 966ceafc7a437105ecfe1cadb3747b2965a260ca ~ 56f87ac2b9543be2be529b831666682e6df4bc40 -
Linux Linux 6.10 -

二、漏洞 CVE-2026-97547 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-97547 的情报信息

请登录查看更多情报信息。

CVE-2026-97547 补丁与修复 (4)

同批安全公告 · Linux · 2026-09-25 · 共 372 条

CVE-2026-100075 9.8 CRITICAL RDMA/srpt:srpt_alloc_rw_ctxs() 未释放计数器修复
CVE-2026-97957 8.8 HIGH hinic 邮箱段缓冲区溢出漏洞
CVE-2026-97527 8.8 HIGH qla2xxx SCSI驱动程序 NVMe未解决上下文列表竞争条件漏洞
CVE-2026-97528 8.8 HIGH QLogic qla2xxx驱动LS拒绝错误NVMe内存泄漏漏洞
CVE-2026-97555 8.8 HIGH smb客户端:修复DACL所有者/组重写中的堆溢出漏洞
CVE-2026-98115 8.8 HIGH ksmbd 注销期间会话安全排空漏洞
CVE-2026-97525 8.2 HIGH x86/mm/pat:内核页表分裂页表分配漏洞
CVE-2026-97573 8.1 HIGH bnxt_en 驱动 bnxt_rx_ring_reset 缓冲区分配失败漏洞
CVE-2026-98070 8.1 HIGH Linux RDS 模块远程代码执行漏洞
CVE-2026-97570 8.1 HIGH bnxt_en: 修复因SW TPA ID绑定问题导致的崩溃漏洞
CVE-2026-98069 8.1 HIGH Net/RDS rds_conn_shutdown() 快速路径锁获取漏洞
CVE-2026-98130 8.1 HIGH SCTP定时器启动竞争条件漏洞
CVE-2026-98116 7.8 HIGH ALSA: PCM内存映射与缓冲区重新分配序列化以修复页面UAF漏洞
CVE-2026-97903 7.8 HIGH exit: proc_flush_pid 线程 PID 持引越界漏洞
CVE-2026-97548 7.8 HIGH XFS rtrmap和rtrefcount _maxlevels_ondisk函数漏洞
CVE-2026-97611 7.8 HIGH Open vSwitch 使用后释放漏洞
CVE-2026-97612 7.8 HIGH MPLS 协议栈在弹出标签时未清除 inner_protocol
CVE-2026-98073 7.8 HIGH Linux 内核网络命名空间更改竞态条件漏洞
CVE-2026-97602 7.8 HIGH Linux内核inet模块队列失效前刷新漏洞
CVE-2026-97577 7.8 HIGH Rockchip RK3588 媒体引擎 AV1 帧容量超限漏洞

显示前 20 条,共 372 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97547

暂无评论


发表评论