CVE-2026-64600
Description
In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared.
If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20- osv-coords15 versionspkg:linux/kernelpkg:rpm/opensuse/dtb-aarch64&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-64kb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default-base&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-docs&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-kvmsmall&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-build&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-qa&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-syms&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-zfcpdump&distro=openSUSE%20Leap%2016.0
>= 4.11.0, < 5.15.212+ 14 more
- (no CPE)range: >= 4.11.0, < 5.15.212
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1.160000.2.19
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 7.1.7-1.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
Patches
Vulnerability mechanics
References
14- git.kernel.org/stable/c/206c09b04dc5469c7ff14d8aceff2d47c88078d9nvdPatch
- git.kernel.org/stable/c/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7nvdPatch
- git.kernel.org/stable/c/44f891bc088958399eec27f7604928694aa35581nvdPatch
- git.kernel.org/stable/c/50f0012da1040f69a4e788cd9aed587c9a04983fnvdPatch
- git.kernel.org/stable/c/b8c9aa832b52680ee40d6cab0efb081f9a69df05nvdPatch
- git.kernel.org/stable/c/dc11be133efca5fe3a2fb02b016dee825cc12f18nvdPatch
- git.kernel.org/stable/c/e705d81a7193dd19e69b8e2bad4696d78a4ea075nvdPatch
- www.openwall.com/lists/oss-security/2026/07/22/14nvdMailing ListExploit
- cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txtnvdExploitThird Party Advisory
- www.openwall.com/lists/oss-security/2026/07/22/18nvdMailing List
- www.openwall.com/lists/oss-security/2026/07/22/19nvdMailing List
- www.openwall.com/lists/oss-security/2026/07/31/3nvdMailing List
- www.openwall.com/lists/oss-security/2026/08/03/4nvdMailing List
- www.openwall.com/lists/oss-security/2026/08/03/8nvdMailing List
News mentions
5- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News · Jul 27, 2026
- Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 StoriesCyber Security News · Jul 26, 2026
- New RefluXFS Linux flaw lets attackers gain root privilegesBleepingComputer · Jul 23, 2026
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL InstallsThe Hacker News · Jul 23, 2026
- RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root AccessCyber Security News · Jul 22, 2026