CVE-2026-97543
In the Linux kernel, the following vulnerability has been resolved: xfs: destroy seen inode bitmap when we fail to add a dirpath LOLLM observes a memory leak in xchk_dirtree_create_path if we create the directory path object but appending the name to the path fails. When this happens, we don't tear down the (empty) seen inode bitmap. This is a pretty trivial error, but let's not leave logic bombs. Do the same for a similar bug in xrep_dirtree_create_adoption_path.
Affected versions
Linux kernel versions
6.10
and later are affected. Fixed in
6.12.111,
6.18.53,
7.2.7,
7.3-rc3
and their respective stable series.
References
4 totalFrequently asked questions
-
What is CVE-2026-97543?
CVE-2026-97543 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.10 onward and has been patched in 6.12.111, 6.18.53, 7.2.7 and others. CVE-2026-97543 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-97543?
Yes. CVE-2026-97543 has been patched. Fixed versions include 6.12.111, 6.18.53, 7.2.7 and others. If you are running Linux kernel 6.10 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-97543 actively exploited?
No. CVE-2026-97543 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.