CVE-2026-64600
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.47%• Percentile: 40%
Techniques & Countermeasures
- CWE-362•Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Affected Systems
- debian•linux
all | < 6.1.180-1 | < 6.12.96-1 | < 7.1.4-1
- debian•linux-6.1
< 6.1.180-1~deb11u1
- debian•linux-6.12
< 6.12.100-1~deb12u1
- ubuntu•linux
all | all | all | all | < 7.0.0-31.31
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
all | all | all | all | < 7.0.0-1012.12
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
all
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.14
all
- ubuntu•linux-aws-6.17
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
all
- ubuntu•linux-aws-7.0
all | < 7.0.0-1012.12~24.04.1
- ubuntu•linux-aws-fips
all
- ubuntu•linux-aws-hwe
all
- ubuntu•linux-azure
all | all | all | all | all
- ubuntu•linux-azure-4.15
all
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
all
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-6.14
all
- ubuntu•linux-azure-6.17
all
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
all
- ubuntu•linux-azure-7.0
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all | all | all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.14
all
- ubuntu•linux-azure-fde-6.17
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fde-7.0
all
- ubuntu•linux-azure-fips
all
- ubuntu•linux-azure-nvidia
all
- ubuntu•linux-azure-nvidia-6.14
all
Showing first 50 affected entries in server-rendered view.
References (48)
- https://git.kernel.org/stable/c/e705d81a7193dd19e69b8e2bad4696d78a4ea075
- https://git.kernel.org/stable/c/206c09b04dc5469c7ff14d8aceff2d47c88078d9
- https://git.kernel.org/stable/c/44f891bc088958399eec27f7604928694aa35581
- https://git.kernel.org/stable/c/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7
- http://www.openwall.com/lists/oss-security/2026/07/22/14
- http://www.openwall.com/lists/oss-security/2026/07/22/18
- http://www.openwall.com/lists/oss-security/2026/07/22/19
- https://git.kernel.org/stable/c/dc11be133efca5fe3a2fb02b016dee825cc12f18
- https://git.kernel.org/stable/c/b8c9aa832b52680ee40d6cab0efb081f9a69df05
- https://git.kernel.org/stable/c/50f0012da1040f69a4e788cd9aed587c9a04983f
- https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt
- http://www.openwall.com/lists/oss-security/2026/07/31/3
- http://www.openwall.com/lists/oss-security/2026/08/03/4
- http://www.openwall.com/lists/oss-security/2026/08/03/8
- https://access.redhat.com/errata/RHBA-2026:39332
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhba-2026_39332.json
- https://access.redhat.com/security/cve/CVE-2026-64600
- https://bugzilla.redhat.com/show_bug.cgi?id=2498915
- https://www.cve.org/CVERecord?id=CVE-2026-64600
- https://nvd.nist.gov/vuln/detail/CVE-2026-64600
- https://access.redhat.com/errata/RHBA-2026:41013
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhba-2026_41013.json
- https://access.redhat.com/errata/RHBA-2026:41254
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhba-2026_41254.json
- https://access.redhat.com/errata/RHSA-2026:46951
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_46951.json
- https://access.redhat.com/errata/RHSA-2026:47981
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_47981.json
- https://access.redhat.com/errata/RHSA-2026:47983
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_47983.json
- https://access.redhat.com/errata/RHSA-2026:47984
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_47984.json
- https://access.redhat.com/errata/RHSA-2026:47997
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_47997.json
- https://access.redhat.com/errata/RHSA-2026:47998
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_47998.json
- https://access.redhat.com/errata/RHSA-2026:48016
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_48016.json
- https://ubuntu.com/security/CVE-2026-64600
- https://www.openwall.com/lists/oss-security/2026/07/22/14
- https://git.kernel.org/linus/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7
- https://security-tracker.debian.org/tracker/CVE-2026-64600
- https://ubuntu.com/security/notices/USN-8726-1
- https://ubuntu.com/security/notices/USN-8727-1
- https://ubuntu.com/security/notices/USN-8728-1
- https://ubuntu.com/security/notices/USN-8760-1
- https://ubuntu.com/security/notices/USN-8726-2