CVE-2026-64600

CVE Details

Release Date:2026-07-21
Impact:Important What is this?

Description


A flaw was found in the XFS filesystem. A race condition in the copy-on-write mechanism for reflinked files can cause writes to bypass the copy-on-write process and modify shared data blocks directly. As a result, data intended for a private copy may be written to the original shared location, corrupting the contents of other files that reference those blocks. A local attacker with read access to a file on an XFS filesystem with reflink enabled could exploit this flaw to corrupt files they do not have write access to, allowing content to be added to the target file. If properly exploited this vulnerability may lead to privilege escalations or arbitrary code execution.

See more information about CVE-2026-64600 from MITRE CVE dictionary and NIST NVD


NOTE: The following CVSS metrics and score provided are preliminary and subject to review.


CVSS v3 metrics

Base Score: 7.8
Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Version: 3.1
Attack Vector: Local
Attack Complexity: Low
Privileges Required: Low
User Interaction: None
Scope: Unchanged
Confidentiality Impact: High
Integrity Impact: High
Availability Impact: High

Errata information


PlatformErrataRelease Date
Oracle Linux version 10 (kernel) ELSA-2026-394942026-07-16
Oracle Linux version 7 (kernel-uek) ELBA-2026-5000092026-07-16
Oracle Linux version 8 (kernel-uek) ELBA-2026-5000092026-07-16
Oracle Linux version 8 (kernel-uek) ELBA-2026-5000102026-07-16
Oracle Linux version 9 (kernel-uek) ELBA-2026-5000102026-07-16


This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections:

software.hardware.complete