CVE-2026-31556
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-31556 is a lock-handling flaw in the Linux kernel's XFS filesystem quota scrub subsystem. The vulnerability exists in the xchk_quota_item function, which can return early after calling xchk_fblock_process_error without releasing the dquot lock (dq->q_qlock), risking lock leaks and deadlocks in subsequent quota operations. It affects Linux kernel versions 6.8.1 through 6.12.79, 6.13 through 6.18.20, 6.19 through 6.19.10, and 7.0 release candidates (rc1–rc7). The vulnerability was disclosed on April 24, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-772 (Missing Release of Resource after Effective Lifetime). In the xchk_quota_item function within the XFS scrub subsystem, when xchk_fblock_process_error returns false, the function exits immediately without calling the corresponding unlock on dq->q_qlock. This unreleased mutex lock can cause subsequent quota operations to block indefinitely, leading to deadlocks. The attack vector is local, requiring low privileges, and no user interaction is needed. The fix involves explicitly unlocking dq->q_qlock before any early return path in the affected function (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation causes the XFS quota subsystem to become unresponsive due to lock leaks or deadlocks, resulting in a denial of service for quota-related filesystem activities and potential degradation of overall system stability. There is no confidentiality or integrity impact; the vulnerability is limited to availability (CVSS availability impact: High). A local attacker with low privileges on a system using XFS with quota enabled could trigger this condition, potentially causing quota operations to hang indefinitely (Red Hat CVE).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. Exploitation requires local access with low privileges, further limiting the practical attack surface (Red Hat CVE).

Mitigation and workarounds

Update the Linux kernel to one of the patched versions: 6.12.80 or later, 6.18.21 or later, 6.19.11 or later, or 7.0 (stable release). Patch commits are available in the Linux kernel stable repository. Systems with high XFS quota subsystem usage should be prioritized for patching to prevent potential deadlocks and service degradation. No configuration-based workaround is documented; upgrading to a fixed kernel version is the recommended remediation (Red Hat CVE, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Fixed

sid

linux: 6.19.11-1

Fixed

trixie

linux: 6.12.85-1

Fixed

Ubuntu

Fixed

bionic

linux

Not Affected

bionic (esm-infra)

linux

Not Affected

bionic (fips-updates)

linux-fips

Not Affected

bionic (fips)

linux-fips

Not Affected

devel

linux

Not Affected

focal

linux

Not Affected

focal (esm-infra)

linux

Not Affected

focal (fips-updates)

linux-fips

Not Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

kernel-rt.src

Affected

RHEL 10

kernel.src

Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-fips
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-fips
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management