Linux XFS reflink flaw could grant root via race condition

Qualys warns of RefluXFS, a nine-year-old race-condition in the XFS reflink feature (CVE-2026-64600) that enables local unprivileged users to overwrite blocks backing protected files and gain root on Linux kernels 4.11+. The attack clones a target file to a scratch file and races concurrent writes in the copy-on-write path, causing disk-block modifications that survive reboot and produce no kernel logs. Affected distros include RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, and CloudLinux, potentially impacting millions. Kernel patches are available and backported; reboot to verify. There are currently no reliable mitigations beyond patching.
- New RefluXFS Linux flaw lets attackers gain root privileges BleepingComputer
- RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) Qualys
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs The Hacker News
- Linux XFS has a decade-old race condition allowing full root access Network World
- Linux Kernel Flaw Exposes 16 Million RHEL Systems to Silent Root Takeover Tech Times
Reading Insights
1
7
4 min
vs 5 min read
88%
818 → 96 words
Want the full story? Read the original article
Read on BleepingComputer