🟡 Medium | Source: Microsoft Security Response Center
CVE-2026-64187 is a vulnerability in the Linux XFS filesystem’s log recovery mechanism, surfaced via Microsoft’s security advisory channel for Azure. The flaw causes the system to fail recovery when encountering a committed log item with no associated regions, which could lead to filesystem corruption or denial of service in affected environments. This is relevant to Azure customers running Linux workloads, particularly those using XFS-formatted volumes.
Security Architect’s Take: Review Azure Linux VMs and managed services using XFS filesystems and ensure the underlying OS kernel is patched to a version that includes the upstream XFS fix. Prioritise instances where XFS volumes hold critical data or where unplanned reboots could trigger log recovery.
Original advisory: CVE-2026-64187 xfs: fail recovery on a committed log item with no regions