CVE Tools
Back to feed
Advisory Linux Kernel privilege-escalation zero-day

RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)

Qualys Security Blog·By Saeed Abbasi··9 min read
CVE Tools coverage

A critical local privilege escalation vulnerability, CVE-2026-64600, has been discovered in the Linux kernel's XFS filesystem. Attackers with basic user access can exploit this flaw to overwrite protected files and gain full root privileges on affected systems, including those using SELinux in Enforcing mode. The issue affects a wide range of enterprise Linux distributions, including RHEL, Oracle Linux, Amazon Linux, and Fedora, especially when running an XFS root filesystem with reflink enabled. The vulnerability has existed since kernel version 4.11 (circa 2017) and may impact over 16 million systems globally. Immediate patching is strongly advised, as no effective workarounds exist.

Executive summary

Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel’s XFS filesystem copy-on-write path. An attacker with an ordinary local account can exploit this race condition to overwrite protected files on disk and gain host root privileges on affected systems, including deployments running SELinux in Enforcing mode.…

Continue reading on Qualys Security Blog