CVE-2026-80529
Published Aug 26, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: xfs: don't swallow dquot recovery verification errors xlog_recover_dquot_commit_pass2() validates the recovered dquot with xfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps to out_release. But out_release unconditionally returns 0, so the corruption error is discarded: the caller xlog_recover_items_pass2() sees success, log recovery proceeds as if the dquot were valid, and the corrupt quota buffer can be written back to disk.
Is your site exposed to CVE-2026-80529?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/36a31b12540c0a0a3b77a01fda86de646f2961fb
https://git.kernel.org/stable/c/38a4dbe588bd028a07a77dc5cee62ee3ce21e87d
https://git.kernel.org/stable/c/5b756fbb60b5d26063f46a11a3c7daa7eb616d79
https://git.kernel.org/stable/c/a233b3362a3c7bf23f5143b4ef4b17ec337fcb4d
https://git.kernel.org/stable/c/e2b4a856085e9bd939bde2dee0d08b1d41babde9
https://git.kernel.org/stable/c/e506e127fcb4e2bad1045805f1740b395eea9618
Frequently Asked Questions
What is CVE-2026-80529? +
In the Linux kernel, the following vulnerability has been resolved:
xfs: don't swallow dquot recovery verification errors
xlog_recover_dquot_commit_pass2() validates the recovered dquot with
xfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps
to out_release. But out_release unconditionally returns 0, so the
corruption error is discarded: the caller xlog_recover_items_pass2()
sees success, log recovery proceeds as if the dquot were valid, and the
corrupt quota buffer can be written back to disk.
How do I check if I'm vulnerable to CVE-2026-80529? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.