CVE-2026-64600
Last modified
CVE-2026-64600 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5, < dc11be133efca5fe3a2fb02b016dee825cc12f18; >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5, < b8c9aa832b52680ee40d6cab0efb081f9a69df05; >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5, < 50f0012da1040f69a4e788cd9aed587c9a04983f; >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5, < e705d81a7193dd19e69b8e2bad4696d78a4ea075; >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5, < 206c09b04dc5469c7ff14d8aceff2d47c88078d9; >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5, < 44f891bc088958399eec27f7604928694aa35581; >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5, < 2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7 |
| Linux | Linux | 4.11 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64600?
How severe is CVE-2026-64600?
How do I fix CVE-2026-64600?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64594In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64595In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64596In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64597In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64598In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-64599In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64601In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64602In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64603In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64604In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64606Deserialization of untrusted data vulnerability that may all…9.8
- CVE-2026-64607HttpClient based on the classic i/o model fails to correctly…5.3
Are you affected by CVE-2026-64600?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
