Race condition in Linux kernel - CVE-2026-64600
Published: July 23, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in xfs_reflink_fill_cow_hole and xfs_reflink_fill_delalloc in the XFS reflink code when processing direct I/O writes after cycling the ILOCK. A local user can trigger a racing direct I/O write operation to cause a denial of service.
The issue occurs because a stale data fork mapping can be used after the ILOCK is dropped and reacquired, which can result in incorrect shared-block state during copy-on-write handling.
How to mitigate CVE-2026-64600
Sources
- https://git.kernel.org/stable/c/206c09b04dc5469c7ff14d8aceff2d47c88078d9
- https://git.kernel.org/stable/c/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7
- https://git.kernel.org/stable/c/44f891bc088958399eec27f7604928694aa35581
- https://git.kernel.org/stable/c/e705d81a7193dd19e69b8e2bad4696d78a4ea075
- http://www.openwall.com/lists/oss-security/2026/07/22/14
- http://www.openwall.com/lists/oss-security/2026/07/22/18
- http://www.openwall.com/lists/oss-security/2026/07/22/19