CVE-2026-31556

Source
https://cve.org/CVERecord?id=CVE-2026-31556
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31556.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-31556
Downstream
Related
Published
2026-04-24T14:35:39.880Z
Modified
2026-07-11T03:54:06.468962251Z
Summary
xfs: scrub: unlock dquot before early return in quota scrub
Details

In the Linux kernel, the following vulnerability has been resolved:

xfs: scrub: unlock dquot before early return in quota scrub

xchkquotaitem can return early after calling xchkfblockprocesserror. When that helper returns false, the function returned immediately without dropping dq->qqlock, which can leave the dquot lock held and risk lock leaks or deadlocks in later quota operations.

Fix this by unlocking dq->q_qlock before the early return.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31556.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7d1f0e167a067ed741dec08b7614d76893422b04
Fixed
e822f535273af0e8968eab7acc0cea0b90dd25af
Fixed
3b0c3414b308e6822cda90bf99f7eac94d4cca2b
Fixed
d128fc0c5c2b19224927d4fd2a46c2fe6a1f606f
Fixed
268378b6ad20569af0d1957992de1c8b16c6e900

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31556.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.12.80
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.21
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31556.json"