Новая уязвимость RefluXFS позволяет получить root-права в Linux
Researchers at Qualys have discovered a nine-year-old flaw in the XFS file system, identified as CVE-2026-64600 and named RefluXFS. This vulnerability allows unprivileged local users to overwrite protected files and gain root privileges by exploiting a race condition during reflink operations. The bug was introduced in Linux 4.11 (released in 2017) and has been present in all subsequent stable kernel versions. Systems using XFS with reflink enabled—common in distributions like Red Hat, CentOS, Oracle Linux, and others—are potentially affected. Researchers estimate over 16.4 million systems could be impacted. A fix was committed on July 16, 2026, and distribution vendors are now rolling out patches. Administrators are urged to update their kernels promptly, especially on public-facing or multi-user systems.