Review reviewHigh

CVE-2026-64600

Linux

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refco...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.23
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refco...

Affected product and versions

Product
Linux
Affected versions
>= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 < dc11be133efca5fe3a2fb02b016dee825cc12f18, >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 < b8c9aa832b52680ee40d6cab0efb081f9a69df05, >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 < 50f0012da1040f69a4e788cd9aed587c9a04983f, >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 < e705d81a7193dd19e69b8e2bad4696d78a4ea075, >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 < 206c09b04dc5469c7ff14d8aceff2d47c88078d9, >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 < 44f891bc088958399eec27f7604928694aa35581, >= 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 < 2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7, >= 4.11
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available