A nine-year-old race condition in the Linux kernel's XFS filesystem (CVE-2026-64600) allows unprivileged attackers to gain root privileges by overwriting protected files. The vulnerability affects systems with XFS reflink enabled, a default configuration on enterprise Linux distributions including RHEL, Fedora, and Amazon Linux.
23 reports · 21 independentother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
⚠️ CRITICAL: RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) A race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root, bypassing SELinux. The flaw affects kernel versions 4.11 and later, potentially impacting over 16 million systems. Any user with local access can exploit this to g… ht
🚨 New Linux Local Privilege Escalation Vulnerability RefluXFS (CVE-2026-64600) is a newly disclosed race condition in the Linux kernel's XFS copy-on-write path that can allow an unprivileged local user to gain root privileges, even on systems with SELinux Enforcing. The flaw affects XFS filesystems with reflink enabled and has existed since Linux kernel 4.11 (2017). Enterprise distributions inclu
🤖 CVE-2026-64600 (RefluXFS): 9-year-old Linux kernel race condition in XFS filesystem lets unprivileged users gain persistent root on default RHEL/Fedora/Amazon Linux installs. PoC published by Qualys. 🔗 https:// thehackernews.com/2026/07/nine -year-old-refluxfs-linux-flaw-gives.html # CVE # Linux # PrivEsc # CyberSec
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. [...]
Dubbed RefluXFS the security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on major enterprise Linux distributions), running Linux kernel v4.11 or later. https://www. bleepingcomputer.com/news/linu x/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/
RefluXFS (CVE-2026-64600) is a race-condition in the Linux kernel's XFS copy-on-write path. (Kernel updates are available.) On an XFS filesystem with reflink enabled (Default on RHEL and similar, plus Amazon Linux), if you win a race during the copy-on-write remap lets the unprivileged local user overwrite the on-disk contents of any readable file on that volume including /etc/passwd or a SUID-roo
Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges. # RefluXFS # CVE202664600 # LinuxKernel # Cybersecurity # XFS https:// meterpreter.org/refluxfs-linux -vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
🐧 SIGINT // Ubuntu Watch — 2026-07-25 A race condition in XFS copy-on-write letting local users get root is nasty for any homelab running XFS volumes, especially containers or NAS boxes. Patch kernels promptly and check exploit PoCs before exposing untrusted local users. 🔗 https:// blog.qualys.com/vulnerabilitie s-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-r
⚠️ CRITICAL: New RefluXFS Linux flaw lets attackers gain root privileges A nine-year-old race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root. Systems running kernel v4.11+ with XFS and reflink enabled are vulnerable. The exploit leaves no kernel logs and persists across reboots, making dete… https:// threatnoir.com/fo
🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability. In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access. ℹ️ Additional
🐧 SIGINT // Ubuntu Watch — 2026-07-26 A 9-year-old race in XFS reflink handling giving root on default installs is the kind of bug that outlives multiple LTS cycles. If you run XFS on shared multi-user boxes, patch kernels now, not later. 🔗 https:// thehackernews.com/2026/07/nine -year-old-refluxfs-linux-flaw-gives.html # Ubuntu # Linux # infosec
CVE-2026-64600, dubbed RefluXFS by Qualys Threat Research Unit, is a nine-year-old race condition that lets a local attacker clone a root-owned file — /etc/passwd, a SUID binary, you name it — then hammer it with concurrent O_DIRECT writes until they win the race and own the box. Highly reliable exploitation. Survives reboot. A beautiful, silent corpse. (2/3)
⚪️ New RefluXFS Vulnerability Enables Root Access on Linux 🗨️ Researchers at Qualys have discovered a nine-year-old vulnerability in the XFS file system. The bug, tracked as CVE-2026-64600 and dubbed RefluXFS, allows a local unprivileged user to overwrite protected files and gain root privileges. According to researchers, the bug was… 🔗 https:// hackmag.com/news/refluxfs?utm_ source=mastodon&utm
New RefluXFS Linux flaw lets attackers gain root privileges https://www. bleepingcomputer.com/news/linu x/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/
The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes. # OVSwrap # CVE202664531 # LinuxKernel # OpenvSwitch # LocalRoot # PrivilegeEscalation https:// securityonline.info/ovswrap-cv e-2026-64531-local-root/?utm_source=mastodon&utm_medium=jetpack_social
🐧 SIGINT // Linux Watch — 2026-07-29 A years-old race condition in the traffic-control subsystem, unearthed by AI-assisted fuzzing, turns local users into root. Patch your kernels; the machines are learning to exploit us faster than we patch. 🔗 https://www. infosecurity-magazine.com/news /ai-linux-kernel-zero-day-net-sched/ # Linux # OpenSource # FOSS
‼️ CVE-2026-43503: DirtyClone is a Linux kernel local privilege escalation (LPE) vulnerability caused by page-cache corruption. PoC: https:// github.com/entra1337/DirtyClone