EGI SVG Advisories

Advisory-EGI-SVG-2026-34

XFS file system vulnerability

Update: 2026-07-25

Date: 2026-07-23

DESCRIPTION

CRITICAL risk vulnerability in the copy-on-write functionality of the XFS file system may lead to privilege escalation. It is extensively described in [R 9].

IDs AND CVSS SCORE

EGI SVG ID : EGI-SVG-2026-34

CVE ID : CVE-2026-64600

CVSSv3 Score:

NOTE:

All running resources MUST be either patched or have mitigation in place or affected services disabled by 2026-07-31 00:00 UTC

Sites failing to act or respond to requests from the EGI CSIRT team risk site suspension. [R 98]

ACTIONS REQUIRED/RECOMMENDED

Sites should take immediate action, either patch (fixed kernels are available for RHEL, Rocky Linux and AlmaLinux) or apply mitigation.

MITIGATION

Follow Red Hat’s mitigation guidance in [R 1]

As a temporary mitigation, review the world-writable directories on the affected
XFS filesystem and remove unnecessary write permissions or move writable directories to a different filesystem where appropriate. 

MORE INFORMATION

At the time of writing, no public exploit has been released but there are some working proof-of-concept such as [R 9].

According to the advisory, systems are potentially affected when:

You can perform some initial checks with the following commands: 

STATUS OF THIS ADVISORY

TLP:CLEAR information - Unlimited distribution

https://advisories.egi.eu/Advisory-EGI-SVG-2026-34

https://advisories.egi.eu/Advisory-SVG-CVE-2026-64600

Minor updates may be made without re-distribution to the sites.

CONTACT AND OTHER INFORMATION ON SVG


This advisory is subject to the Creative Commons licence 
https://creativecommons.org/licenses/by/4.0/ and
the EGI (https://www.egi.eu/) Software Vulnerability Group 
must be credited. ---

Comments or questions should be sent to svg-rat at mailman.egi.eu

Vulnerabilities relevant for EGI can be reported at report-vulnerability at egi.eu

See [R 99] for further details, and other information on SVG.

REFERENCES

CREDITS

SVG was alerted to this vulnerability by CERN Computer Security Office