Update: 2026-07-25
Date: 2026-07-23
CRITICAL risk vulnerability in the copy-on-write functionality of the XFS file system may lead to privilege escalation. It is extensively described in [R 9].
EGI SVG ID : EGI-SVG-2026-34
CVE ID : CVE-2026-64600
CVSSv3 Score:
NOTE:
All running resources MUST be either patched or have mitigation in place or affected services disabled by 2026-07-31 00:00 UTC
Sites failing to act or respond to requests from the EGI CSIRT team risk site suspension. [R 98]
Sites should take immediate action, either patch (fixed kernels are available for RHEL, Rocky Linux and AlmaLinux) or apply mitigation.
Follow Red Hat’s mitigation guidance in [R 1]
As a temporary mitigation, review the world-writable directories on the affected
XFS filesystem and remove unnecessary write permissions or move writable directories
to a different filesystem where appropriate.
At the time of writing, no public exploit has been released but there are some working proof-of-concept such as [R 9].
According to the advisory, systems are potentially affected when:
You can perform some initial checks with the following commands:
xfs_info / | grep reflink=find / -xdev -type d -perm -002 -ls 2>/dev/nullTLP:CLEAR information - Unlimited distribution
https://advisories.egi.eu/Advisory-EGI-SVG-2026-34
https://advisories.egi.eu/Advisory-SVG-CVE-2026-64600
Minor updates may be made without re-distribution to the sites.
This advisory is subject to the Creative Commons licence
https://creativecommons.org/licenses/by/4.0/ and
the EGI (https://www.egi.eu/) Software Vulnerability Group
must be credited. ---
Comments or questions should be sent to svg-rat at mailman.egi.eu
Vulnerabilities relevant for EGI can be reported at report-vulnerability at egi.eu
See [R 99] for further details, and other information on SVG.
[R 2] https://security-tracker.debian.org/tracker/CVE-2026-64600
[R 4] https://errata.build.resf.org/ (RockyLinux)
[R 5] https://errata.almalinux.org/ (AlmaLinux)
[R 8] https://www.openwall.com/lists/oss-security/2026/07/22/14
SVG was alerted to this vulnerability by CERN Computer Security Office