Medium severity5.5NVD Advisory· Published Jul 25, 2026· Updated Aug 17, 2026
CVE-2026-64256
CVE-2026-64256
Description
In the Linux kernel, the following vulnerability has been resolved:
xfs: don't wrap around quota ids in dqiterate
LOLLM noticed that q_id is an unsigned 32-bit variable. If it happens to be set to XFS_DQ_ID_MAX due to a filesystem that actually has a dquot for ID_MAX, then this addition will truncate to zero and the iteration starts over. Fix this by casting to u64.
Affected products
9- osv-coords4 versionspkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweedpkg:apk/chainguard/linux-gcp-6.18pkg:apk/chainguard/linux-gcp-6.18-bootcpkg:linux/kernel
< 7.1.7-1.1+ 3 more
- (no CPE)range: < 7.1.7-1.1
- (no CPE)range: < 6.18.44-r0
- (no CPE)range: < 6.18.44-r0
- (no CPE)range: >= 6.8.0, < 6.12.96
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.