Filesystem unavailability via undersized XFS log rounding
Published May 8, 2026 · Updated May 8, 2026
Improper log rounding in Linux Kernel XFS allows attackers to corrupt logs and leave affected filesystems unmountable. When the superblock omits a log stripe unit, xfs_log.c sets l_iclog_roundoff to 512 instead of the 4 KiB physical sector size, producing torn log writes. Reachability requires a crafted on-disk XFS superblock and 4 KiB physical sectors; the resulting CRC failures can prevent log recovery and mounting.
Summary
What happened
Improper log rounding in Linux Kernel XFS allows attackers to corrupt logs and leave affected filesystems unmountable. When the superblock omits a log stripe unit, xfs_log.c sets l_iclog_roundoff to 512 instead of the 4 KiB physical sector size, producing torn log writes. Reachability requires a crafted on-disk XFS superblock and 4 KiB physical sectors; the resulting CRC failures can prevent log recovery and mounting.
The record
- CVE
- CVE-2026-43365
- Published
- May 8, 2026
- Updated
- May 8, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux Kernel
- Classifications
- T1565.001
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- May 8, 2026CVE publishedPublication date reported by the CVE source.
- May 8, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=5.14
- Affected versionversion=a6a65fef5ef8d0a6a0ce514eb66b2f3dfa777b48 <2ecda4b83749c1fef0c9dea4fd5e8b513aba3e40
- Affected versionversion=a6a65fef5ef8d0a6a0ce514eb66b2f3dfa777b48 <41e91dff2d3974730b5ee50daa8e27ec254cbf91
- Affected versionversion=a6a65fef5ef8d0a6a0ce514eb66b2f3dfa777b48 <446a1f5bb64ba38adb93cb043ff0f7b85e8937ca
- Affected versionversion=a6a65fef5ef8d0a6a0ce514eb66b2f3dfa777b48 <52a8a1ba883defbfe3200baa22cf4cd21985d51a
- Affected versionversion=a6a65fef5ef8d0a6a0ce514eb66b2f3dfa777b48 <5afae524f83d6a18517298491a5624cb0eae5029
- Affected versionversion=a6a65fef5ef8d0a6a0ce514eb66b2f3dfa777b48 <5e7148402dfc4a5b7894d8e97b15e5c2e70924aa
- Affected versionversion=a6a65fef5ef8d0a6a0ce514eb66b2f3dfa777b48 <e88ce9f0536f3b2149afb70625cfc4bd74a4ac6d
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo