---
id: CVE-2026-64356
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  xfs: fix memory leak in xfs_dqinode_metadir_create()

  If xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current
  code returns directly, leaking the allo…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  xfs: fix memory leak in xfs_dqinode_metadir_create()

  If xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current
  code returns directly, leaking the allo…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-401
  - CWE-772
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.13, < 6.18.39'
  - 'linux_kernel >= 6.19, < 7.1.4'
  - linux_kernel = 7.2
patched:
  - linux_kernel 7.1.4
published: '2026-07-25'
updated: '2026-09-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64356'
references:
  - url: 'https://git.kernel.org/stable/c/06a2e6dbaa26c0740ac76dfa66b0aedc78d05820'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/45de375b25060edf46e20abb36521ba530336ceb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c3d3d2212c2966973dd7d603c6c6e6ed6fc7fbe1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64356.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-64356'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2507202'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-64356'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64356'
  - url: >-
      https://lore.kernel.org/linux-cve-announce/2026072519-CVE-2026-64356-d9e2@gregkh/T
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00136
epssPercentile: 0.03425
ingestedAt: '2026-09-05T13:39:56.715Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix memory leak in xfs_dqinode_metadir_create()

If xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current
code returns directly, leaking the allocated update and transaction state.
If the subsequent commit fails, the caller-owned inode reference is left
behind.

Fix this memory leak by routing the create failure path through
xfs_metadir_cancel().  For both create and commit failures, finish and
release any inode returned to the caller, mirroring the unwind pattern in
xfs_metadir_mkdir().

The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. Runtime validation
used kprobe fault injection during `mount -o uquota` on a metadir XFS
image. Injecting xfs_metadir_create() reproduced the old active-update path
that left mount stuck later in mount setup; after this change, the same
injection reported cancel_hits=1 and irele_hits=1. Injecting
xfs_metadir_commit() exercised the old inode-reference leak path; after
this change, it reported irele_hits=1.

## Affected

- `linux_kernel >= 6.13, < 6.18.39`
- `linux_kernel >= 6.19, < 7.1.4`
- `linux_kernel = 7.2`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.1.4`

## Vendor advisories

- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64356.json)
