xfs: resample the data fork mapping after cycling ILOCK
Summary
| CVE | CVE-2026-64600 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-23 06:16:50 UTC |
| Updated | 2026-07-23 06:16:50 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,
a data fork mapping, and a cow fork mapping. Unfortunately, these two
helpers cycle the ILOCK to grab a transaction, which means that the
mappings are stale as soon as we reacquire the ILOCK. Currently we
refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but
we don't refresh the data fork mapping beforehand, which means that the
xfs_bmap_trim_cow in that function queries the refcount btree about the
wrong physical blocks and returns an inaccurate value in *shared.
If *shared is now false, the directio write proceeds with a stale data
fork mapping. Fix this by querying the data fork mapping if the
sequence counter changes across the ILOCK cycle. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 e705d81a7193dd19e69b8e2bad4696d78a4ea075 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 206c09b04dc5469c7ff14d8aceff2d47c88078d9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 44f891bc088958399eec27f7604928694aa35581 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5 2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.11 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.11 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.96 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.39 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.4 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc4 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/44f891bc088958399eec27f7604928694aa35581 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e705d81a7193dd19e69b8e2bad4696d78a4ea075 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/206c09b04dc5469c7ff14d8aceff2d47c88078d9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.