{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  xfs: fix under-reservation of blocks when repairing sf directories  Whilst running QA on XFS for-next as of 7.3-rc2 with MKFS_OPTIONS=\"-n size=8192\", I observed the following (trimmed) dmesg splat:   XFS: Assertion failed: args-\u003etotal \u003e= dp-\u003ei_nblocks - nblks, file: fs/xfs/libxfs/xfs_da_btree.c, line: 2387  WARNING: fs/xfs/xfs_message.c:104 at assfail+0x46/0x4a [xfs], CPU#0: xfs_scrub/1426511  CPU: 0 UID: 0 PID: 1426511 Comm: xfs_scrub Tainted: G        W           7.3.0-rc2-djwx #rc2 PREEMPT(lazy)  6e418570b606a39783b0e7e7b30dc407b965f9e8  Tainted: [W]=WARN  RIP: 0010:assfail+0x46/0x4a [xfs]  RSP: 0018:ffffc900010d7890 EFLAGS: 00010246  RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00000000ffffffd1  RDX: 0000000000000000 RSI: 0000000000000021 RDI: ffffffffa059fd38  RBP: 0000000000000002 R08: 0000000000000000 R09: 0000000000000000  R10: 000000000000000a R11: 000000007fffffff R12: ffffc900010d7940  R13: ffff888368d8f980 R14: ffffc900010d7a48 R15: ffffc900010d78d0  FS:  00007f445c5ce680(0000) GS:ffff8884a97ea000(0000) knlGS:0000000000000000  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033  CR2: 00007f443803b9a8 CR3: 0000000107a4b000 CR4: 00000000003506f0  Call Trace:   \u003cTASK\u003e   xfs_da_grow_inode_int+0x2e0/0x300 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xfs_dir2_grow_inode+0x6e/0x150 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xfs_dir2_sf_to_block+0x149/0x870 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xrep_dir_swap_prep+0xe2/0x110 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xrep_dir_swap+0xfb/0x2f0 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xrep_dir_rebuild_tree+0x99/0x100 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xrep_directory+0x83/0x1c0 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xrep_attempt+0x4f/0x1e0 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xfs_scrub_metadata+0x393/0x5b0 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xfs_ioc_scrubv_metadata+0x306/0x570 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   xfs_file_ioctl+0xa4f/0x1150 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]   __x64_sys_ioctl+0x76/0xc0   do_syscall_64+0x7a/0x3b0   entry_SYSCALL_64_after_hwframe+0x4b/0x53  This is a consequence of commit 0fe77e57588b98, which added the following assertion to xfs_da_grow_inode_int:   ASSERT(args-\u003etotal \u003e= dp-\u003ei_nblocks - nblks);  Tracing this back to xrep_dir_swap_prep, I noticed that the xfs_da_args object that's passed to xfs_dir2_sf_to_block sets args-\u003etotal to 1. This is incorrect because mkfs set the directory block size to 8k and the filesystem block size to 4k.  In other words, args-\u003etotal should be 2 here, not 1.  Dave Chinner tripped over the same problem with the same branch through a different channel -- his test setup set the fs block size to 1k, in which case the directory block size is still set to 4k.  Here, args-\u003etotal should be 4.  Changing the assignment of args-\u003etotal to sc-\u003emp-\u003em_dir_geo-\u003efsbcount makes the assertion go away, but that isn't a complete fix.  In xrep_tempexch_estimate, we also incorrectly assume that a shortform conversion requires 1 fsblock when it should be m_dir_geo-\u003efsbcount. Without that, we can under-reserve space in the transaction and cause a filesystem shutdown.  Note that the xfs_dabuf_nfsb helper will compute the correct value for directories and xattr, so we use that instead of open-coding the logic. Also fix xrep_xattr_swap_prep to assign args-\u003etotal via xfs_dabuf_nfsb to avoid one logic bomb if we ever support multi-fsblock attrs.  Tripped-by: 0fe77e57588b98 (\"xfs: assert the reservation covers each da fork growth\")",
  "id": "DEBIAN-CVE-2026-97549",
  "modified": "2026-09-26T04:47:35.421331126Z",
  "published": "2026-09-25T11:17:05.290Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97549"
    }
  ],
  "upstream": [
    "CVE-2026-97549"
  ]
}