RefluXFS: Critical Linux XFS Privilege Escalation Flaw

A nine-year-old race condition in the Linux kernel's XFS filesystem (CVE-2026-64600) allows unprivileged attackers to gain root privileges by overwriting protected files. The vulnerability affects systems with XFS reflink enabled, a default configuration on enterprise Linux distributions including RHEL, Fedora, and Amazon Linux.

23 reports · 21 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

⚠️ CRITICAL: RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) A race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite prote

mastodon:infosec-exchangeother68d ago kagi ↗

⚠️ CRITICAL: RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) A race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root, bypassing SELinux. The flaw affects kernel versions 4.11 and later, potentially impacting over 16 million systems. Any user with local access can exploit this to g… ht

🚨 New Linux Local Privilege Escalation Vulnerability RefluXFS (CVE-2026-64600) is a newly disclosed race condition in the Linux kernel's XFS copy-on-write path that can allow an unprivileged local us

mastodon:infosec-exchangeother68d ago kagi ↗

🚨 New Linux Local Privilege Escalation Vulnerability RefluXFS (CVE-2026-64600) is a newly disclosed race condition in the Linux kernel's XFS copy-on-write path that can allow an unprivileged local user to gain root privileges, even on systems with SELinux Enforcing. The flaw affects XFS filesystems with reflink enabled and has existed since Linux kernel 4.11 (2017). Enterprise distributions inclu

🤖 CVE-2026-64600 (RefluXFS): 9-year-old Linux kernel race condition in XFS filesystem lets unprivileged users gain persistent root on default RHEL/Fedora/Amazon Linux installs. PoC published by Qualy

mastodon:infosec-exchangeother68d ago kagi ↗

🤖 CVE-2026-64600 (RefluXFS): 9-year-old Linux kernel race condition in XFS filesystem lets unprivileged users gain persistent root on default RHEL/Fedora/Amazon Linux installs. PoC published by Qualys. 🔗 https:// thehackernews.com/2026/07/nine -year-old-refluxfs-linux-flaw-gives.html # CVE # Linux # PrivEsc # CyberSec

Dubbed RefluXFS the security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on major enterprise Linux distributions), running Linux kernel v4.11 or later. ht

mastodon:infosec-exchangeother68d ago kagi ↗

Dubbed RefluXFS the security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on major enterprise Linux distributions), running Linux kernel v4.11 or later. https://www. bleepingcomputer.com/news/linu x/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/

RefluXFS (CVE-2026-64600) is a race-condition in the Linux kernel's XFS copy-on-write path. (Kernel updates are available.) On an XFS filesystem with reflink enabled (Default on RHEL and similar, plus

mastodon:infosec-exchangeother67d ago kagi ↗

RefluXFS (CVE-2026-64600) is a race-condition in the Linux kernel's XFS copy-on-write path. (Kernel updates are available.) On an XFS filesystem with reflink enabled (Default on RHEL and similar, plus Amazon Linux), if you win a race during the copy-on-write remap lets the unprivileged local user overwrite the on-disk contents of any readable file on that volume including /etc/passwd or a SUID-roo

Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges. # RefluXFS # CVE202664600 # LinuxKernel # Cybersecurity

mastodon:infosec-exchangeother67d ago kagi ↗

Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges. # RefluXFS # CVE202664600 # LinuxKernel # Cybersecurity # XFS https:// meterpreter.org/refluxfs-linux -vulnerability/?utm_source=mastodon&utm_medium=jetpack_social

🐧 SIGINT // Ubuntu Watch — 2026-07-25 A race condition in XFS copy-on-write letting local users get root is nasty for any homelab running XFS volumes, especially containers or NAS boxes. Patch kernel

mastodon:fosstodonother66d ago kagi ↗

🐧 SIGINT // Ubuntu Watch — 2026-07-25 A race condition in XFS copy-on-write letting local users get root is nasty for any homelab running XFS volumes, especially containers or NAS boxes. Patch kernels promptly and check exploit PoCs before exposing untrusted local users. 🔗 https:// blog.qualys.com/vulnerabilitie s-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-r

⚠️ CRITICAL: New RefluXFS Linux flaw lets attackers gain root privileges A nine-year-old race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files

mastodon:infosec-exchangeother66d ago kagi ↗

⚠️ CRITICAL: New RefluXFS Linux flaw lets attackers gain root privileges A nine-year-old race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root. Systems running kernel v4.11+ with XFS and reflink enabled are vulnerable. The exploit leaves no kernel logs and persists across reboots, making dete… https:// threatnoir.com/fo

🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability. In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK

mastodon:infosec-exchangeother66d ago kagi ↗

🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability. In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access. ℹ️ Additional

🐧 SIGINT // Ubuntu Watch — 2026-07-26 A 9-year-old race in XFS reflink handling giving root on default installs is the kind of bug that outlives multiple LTS cycles. If you run XFS on shared multi-us

mastodon:fosstodonother65d ago kagi ↗

🐧 SIGINT // Ubuntu Watch — 2026-07-26 A 9-year-old race in XFS reflink handling giving root on default installs is the kind of bug that outlives multiple LTS cycles. If you run XFS on shared multi-user boxes, patch kernels now, not later. 🔗 https:// thehackernews.com/2026/07/nine -year-old-refluxfs-linux-flaw-gives.html # Ubuntu # Linux # infosec

CVE-2026-64600, dubbed RefluXFS by Qualys Threat Research Unit, is a nine-year-old race condition that lets a local attacker clone a root-owned file — /etc/passwd, a SUID binary, you name it — then ha

mastodon:infosec-exchangeother65d ago kagi ↗

CVE-2026-64600, dubbed RefluXFS by Qualys Threat Research Unit, is a nine-year-old race condition that lets a local attacker clone a root-owned file — /etc/passwd, a SUID binary, you name it — then hammer it with concurrent O_DIRECT writes until they win the race and own the box. Highly reliable exploitation. Survives reboot. A beautiful, silent corpse. (2/3)

🐛 SIGINT // Cybersecurity Watch — 2026-07-27 Nine-year-old Linux kernel XFS flaw (RefluXFS, CVE-2026-64600) lets local users gain root on default RHEL, Oracle Linux, Rocky & AlmaLinux installs. https

mastodon:fosstodonother64d ago kagi ↗

🐛 SIGINT // Cybersecurity Watch — 2026-07-27 Nine-year-old Linux kernel XFS flaw (RefluXFS, CVE-2026-64600) lets local users gain root on default RHEL, Oracle Linux, Rocky & AlmaLinux installs. https:// thehackernews.com/2026/07/nine -year-old-refluxfs-linux-flaw-gives.html # CVE # Linux # InfoSec # Cybersecurity

⚪️ New RefluXFS Vulnerability Enables Root Access on Linux 🗨️ Researchers at Qualys have discovered a nine-year-old vulnerability in the XFS file system. The bug, tracked as CVE-2026-64600 and dubbed

mastodon:infosec-exchangeother64d ago kagi ↗

⚪️ New RefluXFS Vulnerability Enables Root Access on Linux 🗨️ Researchers at Qualys have discovered a nine-year-old vulnerability in the XFS file system. The bug, tracked as CVE-2026-64600 and dubbed RefluXFS, allows a local unprivileged user to overwrite protected files and gain root privileges. According to researchers, the bug was… 🔗 https:// hackmag.com/news/refluxfs?utm_ source=mastodon&utm

The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes. # OVSwrap # CVE202664531 # LinuxKernel # OpenvSw

mastodon:infosec-exchangeother63d ago kagi ↗

The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes. # OVSwrap # CVE202664531 # LinuxKernel # OpenvSwitch # LocalRoot # PrivilegeEscalation https:// securityonline.info/ovswrap-cv e-2026-64531-local-root/?utm_source=mastodon&utm_medium=jetpack_social

🐧 SIGINT // Linux Watch — 2026-07-29 A years-old race condition in the traffic-control subsystem, unearthed by AI-assisted fuzzing, turns local users into root. Patch your kernels; the machines are l

mastodon:fosstodonother62d ago kagi ↗

🐧 SIGINT // Linux Watch — 2026-07-29 A years-old race condition in the traffic-control subsystem, unearthed by AI-assisted fuzzing, turns local users into root. Patch your kernels; the machines are learning to exploit us faster than we patch. 🔗 https://www. infosecurity-magazine.com/news /ai-linux-kernel-zero-day-net-sched/ # Linux # OpenSource # FOSS