CVE-2026-64600

Security update for the Linux Kernel

Beschreibung

Im Linux-Kernel wurde die folgende Schwachstelle behoben: xfs: Resample die Daten-Fork-Zuordnung nach dem Zyklieren von ILOCK Die Hilfsfunktionen xfs_reflink_fill_{cow_hole,delalloc} erhalten jeweils ein Inode, eine Daten-Fork-Zuordnung und eine cow-Fork-Zuordnung. Leider zyklisieren diese beiden Hilfsfunktionen den ILOCK, um eine Transaktion zu erfassen, was bedeutet, dass die Zuordnungen veraltet sind, sobald der ILOCK erneut erfasst wird. Derzeit aktualisieren wir die cow-Fork-Zuordnung durch erneutes Aufrufen von xfs_find_trim_cow_extent, aber wir aktualisieren die Daten-Fork-Zuordnung nicht vorher, was bedeutet, dass xfs_bmap_trim_cow in dieser Funktion das Refcount-Baum über falsche physische Blöcke abfragt und einen ungenauen Wert in *shared zurückgibt. Wenn *shared jetzt falsch ist, wird der direkten Schreibvorgang mit einer veralteten Daten-Fork-Zuordnung fortgesetzt. Dies beheben Sie, indem Sie die Daten-Fork-Zuordnung abfragen, wenn sich der Sequenzzähler während des ILOCK-Zyklus ändert.

Metriken

Severity
high
PoC (öffentlich gemeldet)
7.8
Quelle: nvd-v3
39.0 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.5 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-09 12:14 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-08-18 12:38 UTC· nvd@nist.gov
    • CWE: CWE-362
    • CPE Configuration: OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.178 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.145 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.96 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.39 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.1.4 *cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.2:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 4.11 up to (excluding) 5.15.212
    • Reference Type: kernel.org: https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt Types: Exploit, Third Party Advisory
    • Reference Type: kernel.org: https://git.kernel.org/stable/c/206c09b04dc5469c7ff14d8aceff2d47c88078d9 Types: Patch
  2. CVE Modified2026-08-17 05:18 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Affected: Linux, LinuxLinux, Linux
  3. CVE Modified2026-08-03 21:16 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/08/03/8
  4. CVE Modified2026-08-03 18:16 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/08/03/4
  5. CVE Modified2026-07-24 15:19 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Reference: https://git.kernel.org/stable/c/50f0012da1040f69a4e788cd9aed587c9a04983f
    • Reference: https://git.kernel.org/stable/c/b8c9aa832b52680ee40d6cab0efb081f9a69df05
    • Reference: https://git.kernel.org/stable/c/dc11be133efca5fe3a2fb02b016dee825cc12f18
    • Affected: Linux, LinuxLinux, Linux

Betroffene Betriebssysteme

  • linux

    amazon / amazon_linux

  • linux

    suse / basesystem_module15

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux12.0

  • linux

    debian / debian_linux13.0

  • linux

    suse / development_tools_module15

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_aus8.4

  • linux

    redhat / enterprise_linux_aus8.6

  • linux

    redhat / enterprise_linux_eus10.0

  • linux

    redhat / enterprise_linux_eus8.4

  • linux

    redhat / enterprise_linux_eus9.4

  • linux

    redhat / enterprise_linux_eus9.6

  • linux

    redhat / enterprise_linux_tus8.6

  • linux

    redhat / enterprise_linux_tus8.8

  • linux

    redhat / enterprise_linux_update_services_for_sap_solutions8.6

  • linux

    redhat / enterprise_linux_update_services_for_sap_solutions8.8

  • linux

    redhat / enterprise_linux_update_services_for_sap_solutions9.0

  • linux

    redhat / enterprise_linux_update_services_for_sap_solutions9.2

  • linux

    opensuse / leap15.3

  • linux

    opensuse / leap15.4

  • linux

    opensuse / leap15.5

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • AMD

    ProzessorEPYC Series

  • AMD

    ProzessorRyzen

  • arista

    cloudvision_agni2024.4.0 – 2025.2.2

  • arista

    cloudvision_portal2024.2.0 – 2026.1.0

  • arista

    velocloud_edge4.5.0 – 6.4.1

  • arista

    velocloud_gateway

  • arista

    velocloud_orchestrator

  • Dell

    NetWorkerVirtual Edition

  • Dell

    PowerProtect Data Domain7.10.1.70

  • Dell

    PowerProtect Data Domain7.13.1.40

  • Dell

    PowerProtect Data Domain8.3.1.10

  • Dell

    PowerProtect Data Domain8.4.0.0

  • IBM

    QRadar SIEM7.5.0 UP10 IF01

  • IBM

    QRadar SIEM7.5.0 UP11

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • IBM

    Security Guardium12

  • IBM

    Storage Scale6.1.9.5

  • IBM

    Storage Scale6.2.2.0

  • Juniper

    Junos Space24.1R2

  • Oracle

    VM3

  • redhat

    openshift_container_platform4.12 – 4.12.89

  • redhat

    openshift_container_platform4.13 – 4.13.66

  • redhat

    openshift_container_platform4.14 – 4.14.65

  • redhat

    openshift_container_platform4.15 – 4.15.64

Quellen & Referenzen

Verknüpfte CVEs

51 weitere CVEs anzeigen
IDCVE-2026-64600