🟠 High | Source: Microsoft Security Response Center
CVE-2026-64567 is a Linux kernel vulnerability in the btrfs filesystem driver, which fails to properly validate free space cache entries against available pages. This flaw could lead to memory corruption or system instability if exploited. It is relevant to Azure users running Linux virtual machines or services that utilise btrfs on underlying infrastructure.
Security Architect’s Take: Review any Azure Linux VM workloads or container environments using btrfs filesystems and ensure kernel patches are applied promptly once available. Monitor Microsoft’s update guide for patch availability and prioritise patching on internet-facing or multi-tenant Linux workloads.
Original advisory: CVE-2026-64567 btrfs: reject free space cache with more entries than pages