Bug 2498915 (CVE-2026-64600) - CVE-2026-64600 kernel: XFS data corruption using reflink
Summary: CVE-2026-64600 kernel: XFS data corruption using reflink
Keywords:
Status: NEW
Alias: CVE-2026-64600
Deadline: 2026-07-14
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-10 06:47 UTC by OSIDB Bzimport
Modified: 2026-07-22 18:03 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:41013 0 None None None 2026-07-16 14:17:47 UTC
Red Hat Product Errata RHBA-2026:41065 0 None None None 2026-07-16 20:15:07 UTC
Red Hat Product Errata RHBA-2026:41254 0 None None None 2026-07-17 16:21:25 UTC
Red Hat Product Errata RHSA-2026:39179 0 None None None 2026-07-14 11:46:36 UTC
Red Hat Product Errata RHSA-2026:39180 0 None None None 2026-07-14 11:20:08 UTC
Red Hat Product Errata RHSA-2026:39494 0 None None None 2026-07-14 21:14:51 UTC
Red Hat Product Errata RHSA-2026:39984 0 None None None 2026-07-15 13:43:01 UTC
Red Hat Product Errata RHSA-2026:40425 0 None None None 2026-07-15 23:21:11 UTC
Red Hat Product Errata RHSA-2026:41062 0 None None None 2026-07-16 21:26:18 UTC
Red Hat Product Errata RHSA-2026:41063 0 None None None 2026-07-16 21:29:11 UTC
Red Hat Product Errata RHSA-2026:41229 0 None None None 2026-07-17 08:39:12 UTC

Description OSIDB Bzimport 2026-07-10 06:47:49 UTC
reflinking a file may lead cause a data corruption

Comment 3 errata-xmlrpc 2026-07-14 11:20:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:39180 https://access.redhat.com/errata/RHSA-2026:39180

Comment 4 errata-xmlrpc 2026-07-14 11:46:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:39179 https://access.redhat.com/errata/RHSA-2026:39179

Comment 5 errata-xmlrpc 2026-07-14 21:14:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:39494 https://access.redhat.com/errata/RHSA-2026:39494

Comment 6 errata-xmlrpc 2026-07-15 13:43:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:39984 https://access.redhat.com/errata/RHSA-2026:39984

Comment 7 errata-xmlrpc 2026-07-15 23:21:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:40425 https://access.redhat.com/errata/RHSA-2026:40425

Comment 8 errata-xmlrpc 2026-07-16 21:26:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:41062 https://access.redhat.com/errata/RHSA-2026:41062

Comment 9 errata-xmlrpc 2026-07-16 21:29:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:41063 https://access.redhat.com/errata/RHSA-2026:41063

Comment 10 errata-xmlrpc 2026-07-17 08:39:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:41229 https://access.redhat.com/errata/RHSA-2026:41229

Comment 11 Akiyoshi Kurita 2026-07-22 18:03:36 UTC
A public PoC for CVE-2026-64600 has been disclosed:

https://www.openwall.com/lists/oss-security/2026/07/22/14


Note You need to log in before you can comment on or make changes to this bug.