CVE-2026-64357

UnknownEPSS 0.17%

Last modified

CVE-2026-64357 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchmaps reservation limit check xfs_exchmaps_estimate_overhead() adds the bmbt and rmapbt overhead to a local resblks variable, but the final UINT_MAX check still tests req->resblks. That is the reservation value from before the overhead was added. The computed value is stored back in req->resblks and later passed to xfs_trans_alloc(), whose block reservation argument is unsigned int. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchmaps reservation limit check xfs_exchmaps_estimate_overhead() adds the bmbt and rmapbt overhead to a local resblks variable, but the final UINT_MAX check still tests req->resblks. That is the reservation value from before the overhead was added. The computed value is stored back in req->resblks and later passed to xfs_trans_alloc(), whose block reservation argument is unsigned int. Check the computed reservation so the existing limit applies to the value that will be used.

Metrics

EPSS Probability
0.17%

6.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 966ceafc7a437105ecfe1cadb3747b2965a260ca, < c597c8580d50127fc1221b5a5b653a94d49e23e3; >= 966ceafc7a437105ecfe1cadb3747b2965a260ca, < a62ef2d13d6e7270dd5e88c6082bf2d0edcd5112; >= 966ceafc7a437105ecfe1cadb3747b2965a260ca, < 4707344b0d36d1012c8a1716e20167cd3afdd5f1; >= 966ceafc7a437105ecfe1cadb3747b2965a260ca, < 0a5213bbff62b51c7d4999ac8c7e11ea57d00d45
LinuxLinux6.10

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-64357?
In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchmaps reservation limit check xfs_exchmaps_estimate_overhead() adds the bmbt and rmapbt overhead to a local resblks variable, but the final UINT_MAX check still tests req->resblks. That is the reservation value from before the overhead was added. The computed value is stored back in req->resblks and later passed to xfs_trans_alloc(), whose block reservation argument is unsigned int. Check the computed reservation so the existing limit applies to the value that will be used.
How severe is CVE-2026-64357?
Severity scoring for CVE-2026-64357 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2026-64357?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-64357?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST