Re: [LTP] [PATCH v3] cve: reproducer for cve-2026-64600

Martin Doucha <[email protected]> Fri, 31 Jul 2026 15:59:21 +0200
Newsgroups it.linux.lists.ltp
Message-ID <[email protected]>
Hi,
I've test tested this reproducer on affected kernel v6.4 both with and 
without the pressure threads. The version with pressure threads 
commented out was actually 3 times faster in reproducing the race. I 
recommend removing the pressure threads entirely.

One more comment below.

On 7/31/26 09:08, Andrea Cervesato wrote:
> From: Andrea Cervesato <[email protected]>
> 
> Reproducer for CVE-2026-64600 ("RefluXFS"), a race condition in the XFS
> reflink copy-on-write path for direct I/O writes. The bug was introduced
> in kernel v4.11 by commit 3c68d44a2b49 ("xfs: allocate direct I/O COW
> blocks in iomap_begin") and fixed by commit 2f4acd0fcd86 ("xfs: resample
> the data fork mapping after cycling ILOCK").
> 
> Signed-off-by: Andrea Cervesato <[email protected]>
> ---
> This reproducer has been created with the usage of Kimi K3 (as analyzer
> and writer) and DeepSeek v4 Flash (Max) as reviewer, by taking the
> RefluXFS technical paper as input:
> https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt
> 
> On bugged kernel:
> 
> tst_test.c:2047: TINFO: LTP version: 20260529-131-gd12a6186b
> tst_test.c:2050: TINFO: Tested kernel: 7.2.0-rc1-virtme #21 SMP PREEMPT_DYNAMIC Fri Jul 24 10:20:05 CEST 2026 x86_64
> tst_kconfig.c:90: TINFO: Parsing kernel config '/lib/modules/7.2.0-rc1-virtme/build/.config'
> tst_test.c:1875: TINFO: Overall timeout per run is 0h 00m 30s
> cve-2026-64600.c:233: TFAIL: round 0: racing O_DIRECT write to the clone succeeded
> [    1.252815] cve-2026-646
> HINT: You _MAY_ be missing kernel fixes:
> 
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2f4acd0fcd86
> 
> HINT: You _MAY_ be vulnerable to CVE(s):
> 
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64600
> 
> Summary:
> passed   0
> failed   1
> broken   0
> skipped  0
> warnings 0
> 
> On patched kernel:
> 
> tst_test.c:2047: TINFO: LTP version: 20260529-131-gd12a6186b
> tst_test.c:2050: TINFO: Tested kernel: 7.2.0-rc1-virtme #20 SMP PREEMPT_DYNAMIC Fri Jul 24 10:08:53 CEST 2026 x86_64
> tst_kconfig.c:90: TINFO: Parsing kernel config '/lib/modules/7.2.0-rc1-virtme/build/.config'
> tst_test.c:1875: TINFO: Overall timeout per run is 0h 00m 30s
> [    1.665909] clocksource: Watchdog remote CPU 2 read timed out
> [    8.099229] cve-2026-64600 (249) used greatest stack depth: 12216 bytes left
> cve-2026-64600.c:242: TPASS: Source file survived racing O_DIRECT writers
> 
> Summary:
> passed   1
> failed   0
> broken   0
> skipped  0
> warnings 0
> ---
> Changes in v3:
> - use fuzzy loop
> - get blksize from stat()
> - remove cleanup sentence in the description
> - Link to v2: https://lore.kernel.org/[email protected]
> 
> Changes in v2:
> - rename refluxfs.c
> - ensure reflink=1 for mkfs.xfs
> - remove root restore
> - Link to v1: https://lore.kernel.org/[email protected]
> ---
>   runtest/cve              |   1 +
>   testcases/cve/.gitignore |   1 +
>   testcases/cve/refluxfs   | Bin 864544 -> 0 bytes
>   testcases/cve/refluxfs.c | 280 +++++++++++++++++++++++++++++++++++++++++++++++
>   4 files changed, 282 insertions(+)
> 
> diff --git a/runtest/cve b/runtest/cve
> index 99d84270b6efc9afae5bd27adee704603c3092f7..12e614502e9ccd2ef27f9d59ab4f7109c68d8883 100644
> --- a/runtest/cve
> +++ b/runtest/cve
> @@ -101,3 +101,4 @@ cve-2026-43494 io_uring04
>   cve-2026-46300 xfrm02
>   cve-2026-46300-skb-segment xfrm03
>   cve-2026-46331 cve-2026-46331
> +cve-2026-64600 refluxfs

Please move this test before perf_event_open03. No new tests should be 
added below the memory leak comment unless those tests also cause memory 
leaks.

-- 
Martin Doucha   [email protected]
SW Quality Engineer
SUSE LINUX, s.r.o.
CORSO IIa
Krizikova 148/34
186 00 Prague 8
Czech Republic

-- 
Mailing list info: https://lists.linux.it/listinfo/ltp